USPrivacyAtlasState Privacy & Data Security Law Matcher

State Guide

Maryland Privacy & Data Security Laws

Every statute below can apply to a business handling Maryland residents' data, depending on your revenue, the number of Maryland consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

Oct 1, 2025 (enforcement began Apr 1, 2026)
Maryland Online Data Privacy Act
MODPA

One of the strictest state laws: no revenue threshold. Applies at 35,000+ Maryland consumers (excluding payment-only data), or 10,000+ if 20%+ of revenue comes from selling personal data, plus a near-ban on selling sensitive data and a data-minimization-first approach. Notably has no broad nonprofit exemption (only insurance-fraud/first-responder nonprofits), no higher-education exemption, and its HIPAA exemption covers PHI data only, not the whole entity. A 2026 amendment (HB 711, effective Jul 1, 2026) restricted selling personal data to government entities that within the preceding six months engaged in or supported civil immigration enforcement, expanded "precise geolocation data" to cover information identifying a consumer, mobile device, or vehicle within a 1,750-foot radius, and expanded sensitive data to include characteristics a controller infers. (Note: many secondary sources incorrectly cite this as §§14-4601 et seq. — that section is an unrelated Forensic Nurse Examiner Training Grant Program provision; the correct MODPA codification is §14-4701 et seq.)

Md. Code, Com. Law §§ 14-4701–14-4714Read statute →

Data Security & Breach Notification · 1

Varies by state
Maryland data breach notification law
MD Breach Notification

Requires reasonable security procedures and practices. Applies regardless of company size whenever you hold covered personal information about a resident of this state.

Md. Code, Com. Law § 14-3501 et seq.Read statute →

Genetic Privacy · 1

Regulates direct-to-consumer genetic testing companies and/or genetic data generally — typically requiring express consent before collecting, using, or disclosing genetic data, and consent (or destruction) requirements for biological samples.

Md. Code, Com. Law §§ 14-4401 et seq. (Subtitle 44)Read statute →

Children & Minors Online Safety · 1

Requires default privacy-protective settings and data protection impact assessments for products likely accessed by minors. (Note: frequently miscited as §14-4751 — the correct codification is Subtitle 48, §§14-4801 et seq.)

Md. Code, Com. Law §§ 14-4801 et seq. (Subtitle 48)Read statute →