close
close
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Maryland Privacy Law

MD

Maryland (MODPA)

Last updated

MODPA Enacted, in effect

Who this affects: This page tracks Maryland’s MODPA, which governs controllers, processors, and third parties.

Who it applies to: Entities that do business in Maryland or target its residents, and meet: 35,000+ consumers, or 10,000+ consumers and more than 20% of gross revenue from selling data.

Content on this page is not legal advice This page aggregates publicly cited regulatory facts for informational purposes only. It is not legal advice, and DataGrail is not responsible for decisions made in reliance on it. Consult qualified counsel for your specific compliance obligations.
Oct 1, 2025
Effective ↗
Attorney General
Enforced by ↗
$10,000
Maximum penalty per violation ↗
None
Private right of action ↗

The law, in plain English

Must · Can’t · Should

MODPA, distilled to what actually changes your week. Read one column to know your floor, your hard limits, and the further obligations and good practices worth planning for.

Must

  • Answer rights requests within 45 days and appeals in writing within 60 days, telling consumers of any extension and its reason. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. MD-14-4705 “A controller shall respond to a consumer request not later than 45 days after the controller receives the consumer request” Read the statute MD-14-4705 “The controller informs the consumer of the extension and the reason for the extension within the initial 45–day response period” Read the statute MD-14-4705 “A controller shall establish a process for a consumer to appeal the controller’s refusal to act on a consumer rights request within a reasonable period” Read the statute MD-14-4705 “Not later than 60 days after receiving an appeal, a controller shall inform the consumer in writing of any action taken or not taken in response to the appeal” Read the statute
  • Sign a binding contract with each processor setting out instructions, purpose, data types, duration, and both parties' rights. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. MD-14-4708 “If a controller uses a processor to process the personal data of consumers, the controller and the processor shall enter into a contract that governs the processor’s data processing procedures with respect to processing performed on behalf of the controller. (2) The contract shall be binding and shall clearly set forth: (i) Instructions for processing data; (ii) The nature and purpose of processing; (iii) The type of data subject to processing; (iv) The duration of processing; and (v) The rights and obligations of both parties.” Read the statute
  • Conduct and document regular data protection assessments for heightened-risk processing, including one for each algorithm used. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. MD-14-4710 “A controller shall conduct and document, on a regular basis, a data protection assessment for each of the controller’s processing activities that present a heightened risk of harm to a consumer, including an assessment for each algorithm that is used.” Read the statute

Can't

  • Sell sensitive data, or collect, process, or share it unless strictly necessary for a product or service the consumer requested. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. MD-14-4707 “Sell sensitive data” Read the statute MD-14-4707 “collect, process, or share sensitive data concerning a consumer” Read the statute MD-14-4707 “Except where the collection or processing is strictly necessary to provide or maintain a specific product or service requested by the consumer to whom the personal data pertains, collect, process, or share sensitive data concerning a consumer” Read the statute
  • Sell personal data or use it for targeted advertising if you knew or should have known the consumer is under the age of 18 years. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. MD-14-4707 “Process the personal data of a consumer for the purposes of targeted advertising if the controller knew or should have known that the consumer is under the age of 18 years” Read the statute MD-14-4707 “Sell the personal data of a consumer if the controller knew or should have known that the consumer is under the age of 18 years” Read the statute
  • Geofence within 1,750 feet of mental, reproductive, or sexual health sites to identify, track, collect, or notify on health data. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. MD-14-4704 “Use a geofence to establish a virtual boundary that is within 1,750 feet of any mental health facility or reproductive or sexual health facility for the purpose of identifying, tracking, or collecting data from, or sending any notification to a consumer regarding the consumer’s consumer health data” Read the statute

Should

  • Set up commercially reasonable authentication for authorized-agent opt-out requests so you can comply with them. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. MD-14-4706 “A controller shall comply with an opt–out request received from an authorized agent if, using commercially reasonable efforts, the controller is able to authenticate” Read the statute
  • Route all rights requests through a secure, reliable intake method that never requires consumers to create a new account. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. MD-14-4705 “A controller shall establish a secure and reliable method for a consumer to exercise a consumer right under this section” Read the statute MD-14-4707 “A controller may not require a consumer to create a new account in order to exercise a consumer right” Read the statute
  • Make revoking consent at least as easy as giving it, and stop processing as soon as practicable, within 30 days of the request. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. MD-14-4707 “Provide an effective mechanism for a consumer to revoke the consumer’s consent under this section that is at least as easy as the mechanism by which the consumer provided the consumer’s consent” Read the statute MD-14-4707 “the controller shall stop processing the consumer’s personal data as soon as practicable, but not later than 30 days after receiving the request” Read the statute

These are the highlights we judge most important, not everything MODPA requires. The comprehensive law section below covers the full detail, fact by fact, with the statutory text behind every one.

The comprehensive law

Maryland Online Data Privacy Act

MODPA (SB 541) is Maryland’s comprehensive privacy law. Every fact was extracted from the primary statute by the DataGrail regulation engine and is grounded to the cited source. Scan the facts; the exact statutory text sits one click away on each source link.

Status
Enacted, in effect
Archived excerpt — the text we read …y–client privilege or work product protection, the disclosure may not constitute a waiver of that privilege or protection. (h) A data protection assessment conducted under this section: (1) Shall apply to processing activities that occur on or after October 1, 2025; and (2) Is not required for processing activities that occur before October 1, 2025. Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
Effective
October 1, 2025
Archived excerpt — the text we read …y–client privilege or work product protection, the disclosure may not constitute a waiver of that privilege or protection. (h) A data protection assessment conducted under this section: (1) Shall apply to processing activities that occur on or after October 1, 2025; and (2) Is not required for processing activities that occur before October 1, 2025. Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
Signed
May 9, 2024
“Approved by the Governor, May 9, 2024.” View the source
Enforced by
Attorney General
Division of Consumer Protection of the Office of the Attorney General Archived excerpt — the text we read §14–4714. (a) This section applies to an enforcement action under § 14–4713 of this subtitle for an alleged violation that occurs on or before April 1, 2027. (b) Before initiating any action under § 14–4713 of this subtitle, the Division may issue a notice of violation to the controller or processor if the Division determines that a cure is possible. (c) (1) If the Division issues a notice of violation under subsection (b) of this section, the controller or processor shall have at least 60 days to cure the violation after receipt of the notice. … Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
Maximum penalty per violation
$10,000; up to $25,000 (repeat)
Enforced under Title 13; a criminal misdemeanor (up to $1,000 and one year) may also apply. Source for each figure$10,000 · MD-13-410 $25,000 · MD-13-410 “A merchant who engages in a violation of this title is subject to a fine not exceeding $10,000 for each violation.” View the statute
Right to cure
60 days (discretionary, until Apr 1, 2027)
Discretionary: the Division may give 60 days to cure. Only for violations on or before Apr 1, 2027. Archived excerpt — the text we read §14–4714. (a) This section applies to an enforcement action under § 14–4713 of this subtitle for an alleged violation that occurs on or before April 1, 2027. (b) Before initiating any action under § 14–4713 of this subtitle, the Division may issue a notice of violation to the controller or processor if the Division determines that a cure is possible. (c) (1) If the Division issues a notice of violation under subsection (b) of this section, the controller or processor shall have at least 60 days to cure the violation after receipt of the notice. (2) If the controller or processor fails to cure the violation within the time period specified by the Division, the Division may bring an enforcement… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
Private right of action
No private right of action.
Archived excerpt — the text we read …provided in subsection (b) of this section, a violation of this subtitle is: (1) An unfair, abusive, or deceptive trade practice within the meaning of Title 13 of this article; and (2) Subject to the enforcement and penalty provisions contained in Title 13 of this article, except for § 13–408 of this article. (b) This section does not prevent a consumer from pursuing any other remedy provided by law. Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
Universal opt-out signal
Required
Archived excerpt — the text we read …on the controller’s website to a webpage that allows a consumer, or an authorized agent of the consumer, to opt out of the targeted advertising or the sale of the consumer’s personal data; or (ii) On or before October 1, 2025, allowing a consumer to opt out of any processing of the consumer’s personal data for the purposes of targeted advertising, or any sale of personal data, through an opt–out preference signal sent, with the consumer’s consent, by a platform, technology, or mechanism to the controller indicating the consumer’s intent to opt out of the processing or sale. (4) A platform, technology, or mechanism used in accordance with paragraph (3) of this subsection shall: (i) Be consumer–friendly and easy to use by the average consumer; … Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source

Who it applies to

Entities that do business in Maryland or target its residents, and meet: 35,000+ consumers, or 10,000+ consumers and more than 20% of gross revenue from selling data

What the law gives consumers

  • Right to access Archived excerpt — the text we read §14–4705. (a) Nothing in this section may be construed to require a controller to reveal a trade secret. (b) A consumer shall have the right to: (1) Confirm whether a controller is processing the consumer’s personal data; (2) If a controller is processing a consumer’s personal data, access the consumer’s personal data; (3) Considering the nature of the consumer’s personal data and the purposes of the processing of the personal data, correct inaccuracies in the consumer’s personal data; (4) Require a c… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Right to delete Archived excerpt — the text we read …rsonal data; (3) Considering the nature of the consumer’s personal data and the purposes of the processing of the personal data, correct inaccuracies in the consumer’s personal data; (4) Require a controller to delete personal data provided by, or obtained about, the consumer unless retention of the personal data is required by law; (5) If the processing of personal data is done by automatic means, obtain a copy of the consumer’s personal data processed by the controller in a portable and, to the extent technically feasible, read… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Right to correct Archived excerpt — the text we read … (1) Confirm whether a controller is processing the consumer’s personal data; (2) If a controller is processing a consumer’s personal data, access the consumer’s personal data; (3) Considering the nature of the consumer’s personal data and the purposes of the processing of the personal data, correct inaccuracies in the consumer’s personal data; (4) Require a controller to delete personal data provided by, or obtained about, the consumer unless retention of the personal data is required by law; (5) If the processing of persona… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Right to data portability Archived excerpt — the text we read …the consumer’s personal data; (4) Require a controller to delete personal data provided by, or obtained about, the consumer unless retention of the personal data is required by law; (5) If the processing of personal data is done by automatic means, obtain a copy of the consumer’s personal data processed by the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to easily transmit the data to another controller without hindrance; (6) Obtain a list of the categories of third parties to which the controller has disclosed the consumer’s personal data or a list of the categories of… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Right to know the categories of third-party recipients Archived excerpt — the text we read …he extent technically feasible, readily usable format that allows the consumer to easily transmit the data to another controller without hindrance; (6) Obtain a list of the categories of third parties to which the controller has disclosed the consumer’s personal data or a list of the categories of third parties to which the controller has disclosed any consumer’s personal data if the controller does not maintain this information in a format specific to the consumer; and (7) Opt out of the processing of personal data for purposes of: (i) Targeted advertising; (ii) The sale of personal data; or (iii… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Right to opt out of sale Archived excerpt — the text we read …n this information in a format specific to the consumer; and (7) Opt out of the processing of personal data for purposes of: (i) Targeted advertising; (ii) The sale of personal data; or (iii) Profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the consumer. (c) (1) A controller shall establish a secur… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Right to opt out of targeted advertising Archived excerpt — the text we read …s personal data if the controller does not maintain this information in a format specific to the consumer; and (7) Opt out of the processing of personal data for purposes of: (i) Targeted advertising; (ii) The sale of personal data; or (iii) Profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the consumer. … Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Right to opt out of profiling for solely automated significant decisions Archived excerpt — the text we read …and (7) Opt out of the processing of personal data for purposes of: (i) Targeted advertising; (ii) The sale of personal data; or (iii) Profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the consumer. (c) (1) A controller shall establish a secure and reliable method for a consumer to exercise a consumer right under this section. (2) A consumer may exercise a consumer right under this sect… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Sensitive data: collection, processing and sharing prohibited unless strictly necessary; sale prohibited Including data a controller infers from personal data. Inferred data added, and precise geolocation extended to the location of a mobile device or vehicle (14-4701(x)), by 2026 Md. Laws ch. 874 § 1, eff. 2026-07-01, enacted without the Governor's signature; codification pending. Archived excerpt — the text we read §14–4707. (a) A controller may not: (1) Except where the collection or processing is strictly necessary to provide or maintain a specific product or service requested by the consumer to whom the personal data pertains, collect, process, or share sensitive data concerning a consumer; (2) Sell sensitive data; (3) Process personal data in violation of State or federal laws that prohibit unlawful discrimination; (4) Process the personal data of a consu… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Right to appeal Archived excerpt — the text we read …se of ensuring that the consumer’s personal data: (i) Remains deleted from the controller’s records; and (ii) Is not being used for any other purpose. (f) (1) A controller shall establish a process for a consumer to appeal the controller’s refusal to act on a consumer rights request within a reasonable period after the consumer receives the decision. (2) The appeal process shall be: (i) Conspicuously available; and (ii) Similar to the process for submitting requests to initiate an action in accordance wi… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Right against discrimination Archived excerpt — the text we read …wn that the consumer is under the age of 18 years; (5) Sell the personal data of a consumer if the controller knew or should have known that the consumer is under the age of 18 years; (6) Discriminate against a consumer for exercising a consumer right contained in this subtitle, including denying goods or services, charging different prices or rates for goods or services, or providing a different level of quality of goods or services to the consumer; (7) Collect, process, or transfer personal data or publicly available data in a manner that unlawfully discriminates in or otherwise unlawfully makes unavailable the equal enjoyment of goods or servic… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Not granted: Private right of action Archived excerpt — the text we read …provided in subsection (b) of this section, a violation of this subtitle is: (1) An unfair, abusive, or deceptive trade practice within the meaning of Title 13 of this article; and (2) Subject to the enforcement and penalty provisions contained in Title 13 of this article, except for § 13–408 of this article. (b) This section does not prevent a consumer from pursuing any other remedy provided by law. Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source

Who the law governs

  • Controllers Archived excerpt — the text we read … the election of a majority of the directors of a business, or individuals exercising similar functions; or (3) The power to exercise a controlling influence over the management of a business. (k) “Controller” means a person that, alone or jointly with others, determines the purpose and means of processing personal data. (l) “COPPA” means the federal Children’s Online Privacy Protection Act of 1998 and the regulations, rules, guidance, and exemptions adopted under the Act, and as the Act and the regulations, rules, guidance, a… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Processors Archived excerpt — the text we read … set of operations performed by manual or automated means on personal data. (2) “Process” includes collecting, using, storing, disclosing, analyzing, deleting, or modifying personal data. (z) “Processor” means a person that processes personal data on behalf of a controller. (aa) “Profiling” means any form of automated processing performed on personal data to evaluate, analyze, or predict personal aspects related to an identified or identifiable consumer’s economic situation, health,… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Third parties Archived excerpt — the text we read §14–4709. (a) If a third party uses or shares a consumer’s information in a manner inconsistent with promises made to the consumer at the time of collection of the information, the third party shall provide an affected consumer with notice of the new or changed practice before implementing the new or changed practice. (b) The notice provided under subsection (a) of this section shall be provided in a manner and at a time reasonably calculated to allow a consumer to exercise the rights provided under this subtitle. Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source

Exemptions

  • State and local government bodies (State units and political subdivisions) Archived excerpt — the text we read §14–4703. (a) This subtitle does not apply to: (1) A regulatory, administrative, advisory, executive, appointive, legislative, judicial body or instrumentality of the State, including a board, bureau, commission, or unit of the State or a political subdivision of the State; (2) A national securities association that is registered under § 15 of the federal Securities Exchange Act of 1934 or a registered futures association designated in accordance with § 17 of the federal C… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • National securities associations and registered futures associations Archived excerpt — the text we read …tive, advisory, executive, appointive, legislative, judicial body or instrumentality of the State, including a board, bureau, commission, or unit of the State or a political subdivision of the State; (2) A national securities association that is registered under § 15 of the federal Securities Exchange Act of 1934 or a registered futures association designated in accordance with § 17 of the federal Commodity Exchange Act; (3) A financial institution, an affiliate of a financial institution, or data that is subject to Title V of the federal Gramm–Leach–Bliley Act and regulations adopted under that act; or … Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • GLBA: financial institutions, their affiliates, and data subject to Title V Entity- and data-level Archived excerpt — the text we read …ssociation that is registered under § 15 of the federal Securities Exchange Act of 1934 or a registered futures association designated in accordance with § 17 of the federal Commodity Exchange Act; (3) A financial institution, an affiliate of a financial institution, or data that is subject to Title V of the federal Gramm–Leach–Bliley Act and regulations adopted under that act; or (4) A nonprofit controller that processes or shares personal data solely for the purposes of assisting: (i) Law enforcement agencies in… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Nonprofits solely aiding insurance-fraud probes/responders Nonprofit controllers acting solely to assist law enforcement with insurance-related criminal or fraud investigations, or first responders with catastrophic events. Archived excerpt — the text we read … (3) A financial institution, an affiliate of a financial institution, or data that is subject to Title V of the federal Gramm–Leach–Bliley Act and regulations adopted under that act; or (4) A nonprofit controller that processes or shares personal data solely for the purposes of assisting: (i) Law enforcement agencies in investigating criminal or fraudulent acts relating to insurance; or (ii) First responders in responding to catastrophic events. (b) The following information and data are exempt from this subtitle: (1) Protected health information under HIPAA; (2) Patient–identifying information for purposes of 42 U.S… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • HIPAA protected health information Archived excerpt — the text we read …lent acts relating to insurance; or (ii) First responders in responding to catastrophic events. (b) The following information and data are exempt from this subtitle: (1) Protected health information under HIPAA; (2) Patient–identifying information for purposes of 42 U.S.C. § 290dd–2; (3) Identifiable private information that is used for purpo… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Substance use disorder patient records Archived excerpt — the text we read … First responders in responding to catastrophic events. (b) The following information and data are exempt from this subtitle: (1) Protected health information under HIPAA; (2) Patient–identifying information for purposes of 42 U.S.C. § 290dd–2; (3) Identifiable private information that is used for purposes of the federal policy for the protection of human subjects in accordance with 45 C.F.R… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Human subjects research under federal policy Archived excerpt — the text we read … (1) Protected health information under HIPAA; (2) Patient–identifying information for purposes of 42 U.S.C. § 290dd–2; (3) Identifiable private information that is used for purposes of the federal policy for the protection of human subjects in accordance with 45 C.F.R. § 46; (4) Identifiable private information to the extent that it is collected and used as part of human subjects research in accordance with the ICH 36 Good Clinical Practice Guidelines issued by the Internat… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Human subjects research under ICH/FDA guidelines Archived excerpt — the text we read … (3) Identifiable private information that is used for purposes of the federal policy for the protection of human subjects in accordance with 45 C.F.R. § 46; (4) Identifiable private information to the extent that it is collected and used as part of human subjects research in accordance with the ICH 36 Good Clinical Practice Guidelines issued by the International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use or the protection of human subjects under 21 C.F.R. §§ 50 and 56; (5) Patient safety work… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Patient safety work product Archived excerpt — the text we read …Practice Guidelines issued by the International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use or the protection of human subjects under 21 C.F.R. §§ 50 and 56; (5) Patient safety work product that is created and used for purposes of patient safety improvement in accordance with 42 C.F.R. § 3, established in accordance with 42 U.S.C. §§ 299b–21 through 299b–26; (6) (i) Information to the extent it is used for public health, community health, or population health activities and purposes, as… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Public/community/population health information, as authorized by HIPAA When provided by or to a covered entity or business associate. Archived excerpt — the text we read …t safety work product that is created and used for purposes of patient safety improvement in accordance with 42 C.F.R. § 3, established in accordance with 42 U.S.C. §§ 299b–21 through 299b–26; (6) (i) Information to the extent it is used for public health, community health, or population health activities and purposes, as authorized by HIPAA, when provided by or to a covered entity or when provided by or to a business associate in accordance with the business associate agreement with a covered entity; (ii) Information that is a medical record under § 4–301 of the Health – General Article if: 1. The information is held by an entity that is a covered entity or busine… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Medical records held by HIPAA entities to HIPAA standards Medical records (Health-Gen. § 4-301) held by a HIPAA covered entity/business associate that applies HIPAA-equivalent standards (incl. legally protected health care). Archived excerpt — the text we read …poses, as authorized by HIPAA, when provided by or to a covered entity or when provided by or to a business associate in accordance with the business associate agreement with a covered entity; (ii) Information that is a medical record under § 4–301 of the Health – General Article if: 1. The information is held by an entity that is a covered entity or business associate under HIPAA because it collects, uses, or discloses protected health information; and 2. The entity applies the same standards for the collection, use, and disclosure of the information as required for protected health information under HIPAA and medical records under § 4–301 of the Health – General Article, including specific standards regarding legally protected health care; and (iii) Information that is de–identified in accordance with the requirements for de–identification set forth in 45 C.F.R. 164.514 that is derived from individually identifiable health information… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • HIPAA de-identified data Archived excerpt — the text we read …equired for protected health information under HIPAA and medical records under § 4–301 of the Health – General Article, including specific standards regarding legally protected health care; and (iii) Information that is de–identified in accordance with the requirements for de–identification set forth in 45 C.F.R. 164.514 that is derived from individually identifiable health information as described in HIPAA or personal information consistent with the human subject protection requirements of the U.S. Food and Drug Administration; … Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • FCRA-regulated data Archived excerpt — the text we read …, character, general reputation, personal characteristics, or mode of living by a consumer reporting agency, furnisher, or user that provides information for use in a consumer report, and by a user of a consumer report, but only to the extent that the activity is regulated by and authorized under the federal Fair Credit Reporting Act; (8) Personal data collected, processed, sold, or disclosed in compliance with the federal Driver’s Privacy Protection Act of 1994; (9) Pe… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Driver's Privacy Protection Act data Md. Code, Com. Law § 14-4703(b)(8) (2026 Md. Laws ch. 874 § 1) Personal data collected, processed, sold, or disclosed as required by the federal DPPA. 14-4703(b)(8) as amended by 2026 Md. Laws ch. 874, eff. 2026-07-01; codification pending. Archived excerpt — the text we read …1–1201 of this article. 14–4703. (b) The following information and data are exempt from this subtitle: (8) Personal data collected, processed, sold, or disclosed [in compliance] TO THE EXTENT NECESSARY TO COMPLY with AS REQUIRED BY the federal Driver’s Privacy Protection Act of 1994; 14–4707. (a) A controller may not: (1) Except where the collection or processing is strictly necessary to provide or maintain a specific product or service requested by the consumer to whom the personal data pertain… Archived from source — captured 2026-09-28 · snapshot bbe1ba8b Verify at the source
  • FERPA-regulated data Archived excerpt — the text we read …ct; (8) Personal data collected, processed, sold, or disclosed in compliance with the federal Driver’s Privacy Protection Act of 1994; (9) Personal data regulated by the federal Family Educational Rights and Privacy Act; (10) Personal data collected, processed, sold, or disclosed in compliance with the federal Farm Credit Act; (11) Data processed or maintained: (i) In the course of a… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Farm Credit Act data Archived excerpt — the text we read …cessed, sold, or disclosed in compliance with the federal Driver’s Privacy Protection Act of 1994; (9) Personal data regulated by the federal Family Educational Rights and Privacy Act; (10) Personal data collected, processed, sold, or disclosed in compliance with the federal Farm Credit Act; (11) Data processed or maintained: (i) In the course of an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or thi… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Employment data Archived excerpt — the text we read …ts and Privacy Act; (10) Personal data collected, processed, sold, or disclosed in compliance with the federal Farm Credit Act; (11) Data processed or maintained: (i) In the course of an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party, to the extent that the data is collected and used within the context of the role; (ii) As the emergency contact information of a consumer if the data is used for emergency contact purposes; or (iii) That is: 1. Necessary to r… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Emergency contact information Archived excerpt — the text we read …ng to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party, to the extent that the data is collected and used within the context of the role; (ii) As the emergency contact information of a consumer if the data is used for emergency contact purposes; or (iii) That is: 1. Necessary to retain to administer benefits for another individual relating to the consumer who is the subject of the information under item (i)… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Benefits administration data Archived excerpt — the text we read …xt of the role; (ii) As the emergency contact information of a consumer if the data is used for emergency contact purposes; or (iii) That is: 1. Necessary to retain to administer benefits for another individual relating to the consumer who is the subject of the information under item (i) of this item; and 2. Used for the purposes of administering the benefits; (12) Personal data collected, processed, sold, or disclosed in relation to price, route, or service by an air c… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Airline Deregulation Act preemption Archived excerpt — the text we read …ther individual relating to the consumer who is the subject of the information under item (i) of this item; and 2. Used for the purposes of administering the benefits; (12) Personal data collected, processed, sold, or disclosed in relation to price, route, or service by an air carrier subject to the federal Airline Deregulation Act to the extent this subtitle is preempted by the federal Airline Deregulation Act; and (13) Personal data collected by or on behalf of a person regulated under the Insurance Article or an affiliate of such… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Insurance business data Archived excerpt — the text we read …sclosed in relation to price, route, or service by an air carrier subject to the federal Airline Deregulation Act to the extent this subtitle is preempted by the federal Airline Deregulation Act; and (13) Personal data collected by or on behalf of a person regulated under the Insurance Article or an affiliate of such a person, in furtherance of the business of insurance. (c) Controllers and processors that comply with the verifiable parental consent requirements of COPPA shall be considered compliant with an obligation to obtain parental consent in accordance with this subtit… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Personal or household activities Archived excerpt — the text we read …dversely affects the rights or freedoms of any person, including the rights of a person to freedom of speech or freedom of the press as guaranteed in the First Amendment to the U.S. Constitution; or (2) Apply to a person’s processing of personal data during the person’s personal or household activities. (f) If a controller or processor processes personal data in accordance with an exemption under this section, the controller or processor shall demonstrate that the processing: (1) Qualifies f… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Evidentiary privilege (compliance would violate a Maryland evidentiary privilege) Archived excerpt — the text we read … A. The provision of a product or service specifically requested by a consumer; or B. The performance of a contract to which the consumer is a party. (c) (1) An obligation imposed on a controller or a processor under this subtitle does not apply when compliance by the controller or processor with the subtitle would violate an evidentiary privilege under State law. (2) Nothing in this subtitle may be construed to prevent a controller or processor from providing personal data concerning a consumer to a person covered by an evidentiary privilege under State law as … Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Privileged communications to a person covered by an evidentiary privilege Archived excerpt — the text we read …ion imposed on a controller or a processor under this subtitle does not apply when compliance by the controller or processor with the subtitle would violate an evidentiary privilege under State law. (2) Nothing in this subtitle may be construed to prevent a controller or processor from providing personal data concerning a consumer to a person covered by an evidentiary privilege under State law as part of a privileged communication. (d) (1) A controller or processor that discloses personal data to a processor or a third–party controller in compliance with this subtitle is not in violati… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source
  • Rights and freedoms of others, including free speech and press Archived excerpt — the text we read …r the independent misconduct of the controller or processor from which the third–party controller or processor received the personal data. (e) Nothing in this subtitle may be construed to: (1) Impose an obligation on a controller or a processor that adversely affects the rights or freedoms of any person, including the rights of a person to freedom of speech or freedom of the press as guaranteed in the First Amendment to the U.S. Constitution; or (2) Apply to a person’s processing of personal data during the person’s personal or household activities. (f) If a controller or processor processes personal data in accordance with an exe… Archived from source — captured 2026-08-03 · snapshot 4147c7d4 Verify at the source

Published Sep 30, 2026 from the DataGrail regulation engine; each fact links to its primary source.

Timeline

MODPA milestones

This state currently has one dated milestone on the books.

Enforcement October 1, 2025

MODPA took effect

Enforcement began — obligations have been live since this date.

Source: primary citation

Published Sep 30, 2026 from the DataGrail regulation engine; each fact links to its primary source. Reference only, not legal advice.

When staying on top of the law isn't enough, DataGrail automates the work.
DSR automation and regulatory tracking — handled by the platform behind this reference.
How DataGrail helps
Back to the Regulations Hub Reference only — not legal advice. Published Sep 30, 2026