State Guide
Maryland Privacy & Data Security Laws
Every statute below can apply to a business handling Maryland residents' data, depending on your revenue, the number of Maryland consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
One of the strictest state laws: no revenue threshold. Applies at 35,000+ Maryland consumers (excluding payment-only data), or 10,000+ if 20%+ of revenue comes from selling personal data, plus a near-ban on selling sensitive data and a data-minimization-first approach. Notably has no broad nonprofit exemption (only insurance-fraud/first-responder nonprofits), no higher-education exemption, and its HIPAA exemption covers PHI data only, not the whole entity. A 2026 amendment (HB 711, effective Jul 1, 2026) restricted selling personal data to government entities that within the preceding six months engaged in or supported civil immigration enforcement, expanded "precise geolocation data" to cover information identifying a consumer, mobile device, or vehicle within a 1,750-foot radius, and expanded sensitive data to include characteristics a controller infers. (Note: many secondary sources incorrectly cite this as §§14-4601 et seq. — that section is an unrelated Forensic Nurse Examiner Training Grant Program provision; the correct MODPA codification is §14-4701 et seq.)
Data Security & Breach Notification · 1
Requires reasonable security procedures and practices. Applies regardless of company size whenever you hold covered personal information about a resident of this state.
Genetic Privacy · 1
Regulates direct-to-consumer genetic testing companies and/or genetic data generally — typically requiring express consent before collecting, using, or disclosing genetic data, and consent (or destruction) requirements for biological samples.
Children & Minors Online Safety · 1
Requires default privacy-protective settings and data protection impact assessments for products likely accessed by minors. (Note: frequently miscited as §14-4751 — the correct codification is Subtitle 48, §§14-4801 et seq.)