Maryland Privacy Law (MODPA): Compliance Guide
The Maryland Online Data Privacy Act (SB 541), effective October 1, 2025, is the strictest state privacy law in the country. It bans the sale of sensitive data outright — not opt-out, not opt-in, prohibited — restricts processing of sensitive data to what is strictly necessary, and imposes a genuine data-minimization duty that limits collection to what is reasonably necessary. With low 35,000/10,000 thresholds and GPC mandatory from day one, Maryland forces a real redesign of data practices, not just a link in the footer.
- Effective
- October 1, 2025
- GPC / universal opt-out
- Required since October 1, 2025
- Required link text
- “Your Privacy Choices”
Last reviewed July 19, 2026 · Maryland Online Data Privacy Act (SB 541)
Applicability
Who must comply with the MODPA
The Maryland Online Data Privacy Act applies to businesses that meet the following criteria:
- Controls or processes the personal data of 35,000 or more Maryland consumers, or
- Controls or processes the personal data of 10,000 or more Maryland consumers and derives 20% or more of gross revenue from the sale of personal data
Consumer rights
What Maryland consumers can demand
- Right to access personal data
- Right to correct inaccuracies
- Right to delete personal data
- Right to data portability
- Right to opt out of the sale of personal data, targeted advertising, and profiling
Opt-out mechanics
Maryland opt-out & GPC requirements
Like every US state privacy law, the MODPA uses an opt-out model: you do not need a GDPR-style cookie banner, but you must provide a clear and conspicuous opt-out link. The accepted text for Maryland is “Your Privacy Choices”.
Global Privacy Control: Required since October 1, 2025
Maryland requires covered businesses to honor Global Privacy Control signals. The requirement took effect October 1, 2025 — the same day the law itself did.
Enforcement
MODPA penalties & enforcement
- Up to $10,000 per violation
- Up to $25,000 per violation for repeat violations
Cure period: 60-day cure period, available until April 1, 2027.
State quirks
What makes Maryland different
Maryland rewrote three assumptions of the US privacy model. First, sensitive data simply cannot be sold — a flat prohibition no other state matches — and processing it is limited to strict necessity. Second, its minimization rule uses a “reasonably necessary” standard rather than the looser “compatible with disclosed purposes” test, which curtails collect-now-justify-later practices. Third, the penalties scale: $10,000 per violation rising to $25,000 for repeat violations, with the 60-day cure period sunsetting April 1, 2027.
Sensitive data sale banned
The sale of sensitive data is prohibited entirely — not opt-out, not opt-in, banned. Processing sensitive data is restricted to what is strictly necessary.
True data minimization
Collection is limited to what is reasonably necessary — a stricter test than the “compatible with disclosed purposes” standard used by other states.
Universal opt-out from day one
Global Privacy Control must be honored since October 1, 2025, the law's own effective date.
Automation
How ConsentKit handles Maryland
- ConsentKit's widget is served from Cloudflare's edge and receives the visitor's US state server-side, so Maryland visitors are identified before any consent UI renders — no client-side geo-lookup delay.
- Maryland visitors see a persistent “Your Privacy Choices” link — the exact statutory text — available to new and returning visitors alike.
- Because Maryland requires universal opt-out signals, ConsentKit automatically honors Global Privacy Control for Maryland visitors: when the browser broadcasts GPC, the widget applies the opt-out and denies analytics and marketing categories with no click required.
- Every opt-out is recorded server-side with a timestamp and jurisdiction metadata, reviewable and exportable (CSV) from the dashboard — the audit trail regulators ask for.
- Google Consent Mode v2 stays in sync: analytics and advertising tags update the moment a Maryland visitor makes a choice.
Maryland's strictness makes enforcement speed matter: the moment a Maryland visitor opts out — by link or by GPC signal — ConsentKit denies analytics and marketing categories and records the choice.
FAQ
Maryland MODPA FAQ
Why is Maryland's MODPA considered the strictest state privacy law?
Two reasons stand out. It bans the sale of sensitive data outright — prohibited entirely, not just opt-out or opt-in — and restricts processing of sensitive data to what is strictly necessary. On top of that, its data-minimization rule limits collection to what is reasonably necessary, a stricter test than the “compatible with disclosed purposes” standard used elsewhere.
Does the MODPA apply to my business?
Quite possibly: coverage starts at 35,000 Maryland consumers, or just 10,000 consumers when 20% or more of gross revenue comes from selling personal data — among the lowest thresholds in the country.
Is Global Privacy Control mandatory in Maryland?
Yes, since October 1, 2025 — the same day the law took effect. There was no phase-in window: covered businesses had to honor GPC signals from day one.
What are the penalties in Maryland?
Up to $10,000 per violation, rising to $25,000 for repeat violations. A 60-day cure period is available, but only until April 1, 2027 — after that, violations carry full exposure immediately.
This guide is for informational purposes and is not legal advice. Work with qualified counsel to confirm your obligations under the MODPA.
Comply with Maryland's MODPA — and the other 19 state laws
ConsentKit detects each visitor's state at the Cloudflare edge, renders the exact opt-out link their law requires, honors GPC automatically where mandated, and records every choice for your audit trail.