πŸ‡ΊπŸ‡ΈMaryland Online Data Privacy Act

← Back to laws in United States

Maryland Online Data Privacy Act

Maryland Online Data Privacy Act

Maryland Online Data Privacy Act is part of the United States state privacy-law framework. It regulates covered processing of personal data about Maryland residents and must be assessed separately from federal sectoral laws and other states' statutes.

Current official version

Effective status: October 1, 2025

Citation: Md. Code, Commercial Law ss. 14-4601 through 14-4614

Source basis: Maryland Chapter 455 of 2024 and the current Commercial Law provisions.

Scope and applicability

The Act applies to persons conducting business in Maryland or targeting Maryland residents that meet the statutory 35,000-consumer threshold or the lower threshold combined with more than 20 percent of gross revenue from sale. Exemptions are narrower than in several peer statutes.

Thresholds must be calculated using the law's defined consumer population and lookback period. Exemptions should be recorded at entity, data and processing-activity level; an exemption covering one regulated dataset should not automatically be applied to unrelated marketing, website, workforce or customer-support data.

Consumer rights

Consumers may access, correct and delete personal data, obtain portable data, obtain a list of third parties to which data was disclosed and opt out of targeted advertising, sale and qualifying profiling. Appeals and authorized-agent opt-outs are required.

The operational workflow should authenticate requests without collecting excessive new data, meet the applicable response period, document extensions and denials, propagate deletion and opt-out decisions where required, and preserve evidence of the response and any appeal.

Controller and processor duties

Controllers must limit collection to what is reasonably necessary and proportionate, restrict sensitive-data collection and sale, avoid discriminatory processing, publish notices, secure data, contract with processors and assess high-risk processing.

Processor agreements should identify instructions, purpose, duration, data types, confidentiality, subprocessor controls, deletion or return, audit information and assistance with rights, security, breach response and assessments to the extent required by the statute.

State-specific point

Maryland is stricter than the common state-law model. It limits collection rather than merely requiring disclosure, prohibits sale of sensitive data, limits sale of data to what is necessary to provide or maintain a requested product or service, and restricts targeted advertising to consumers known or reasonably known to be under 18.

Enforcement and evidence

The Maryland Attorney General enforces the Act through the Maryland Consumer Protection Act. A violation is an unfair, abusive or deceptive trade practice; the Act does not itself create a private right of action.

Maintain an applicability memorandum, data map, notice versions, request and appeal logs, consent and opt-out records, processor contracts, assessment records, security evidence and a dated record of the official statutory version used. Recheck the official legislature and regulator sources before each scheduled legal review.

What this means for you

Use a shared multi-state privacy operating model, but configure it for this law's exact scope, exemptions, rights, deadlines, consent rules, opt-out signals, assessment triggers and enforcement provisions. Do not substitute a generic US privacy checklist for the state-specific controls.

Other laws in United States
CA-DELETE

California Delete Act and Data Broker Requirements

California Privacy Protection Agency

CPPA

California Privacy Rights Act and California Privacy Protection Agency provisions

California Privacy Protection Agency

CLOUD-ACT

Clarifying Lawful Overseas Use of Data Act (CLOUD Act)

United States Department of Justice

42-CFR-P2

Confidentiality of Substance Use Disorder Patient Records

U.S. Department of Health and Human Services, Office for Civil Rights

CAN-SPAM

Controlling the Assault of Non-Solicited Pornography And Marketing Act

Federal Trade Commission

CPNI

Customer Proprietary Network Information Rules

Federal Communications Commission

DPPA

Drivers Privacy Protection Act

United States Department of Justice and federal courts

ECPA-SCA

Electronic Communications Privacy Act and Stored Communications Act

United States Department of Justice

FERPA

Family Educational Rights and Privacy Act

U.S. Department of Education, Student Privacy Policy Office

GINA

Genetic Information Nondiscrimination Act

U.S. Equal Employment Opportunity Commission and federal health agencies

HITECH

Health Information Technology for Economic and Clinical Health Act

U.S. Department of Health and Human Services, Office for Civil Rights

HIPAA

Health Insurance Portability and Accountability Act of 1996

U.S. Department of Health and Human Services Office for Civil Rights

IL-BIPA

Illinois Biometric Information Privacy Act

Illinois Attorney General and private enforcement

MT-CDPA

Montana Consumer Data Privacy Act

Montana Attorney General, Office of Consumer Protection

NJDPA

New Jersey Data Privacy Law

New Jersey Attorney General and Division of Consumer Affairs

PRIVACY-ACT

Privacy Act of 1974

U.S. Department of Justice, Office of Privacy and Civil Liberties

RI-DTPPA

Rhode Island Data Transparency and Privacy Protection Act

Rhode Island Attorney General

UCPA

Utah Consumer Privacy Act

Utah Attorney General and Division of Consumer Protection

VT-DPOSA

Vermont Data Privacy and Online Surveillance Act

Vermont Attorney General

VPPA

Video Privacy Protection Act

United States Department of Justice and federal courts