USPrivacyAtlasState Privacy & Data Security Law Matcher

State Guide

Maryland Privacy & Data Security Laws

Every statute below can apply to a business handling Maryland residents' data, depending on your revenue, the number of Maryland consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

Oct 1, 2025 (enforcement began Apr 1, 2026)
Maryland Online Data Privacy Act
MODPA

One of the strictest state laws: no revenue threshold. Applies at 35,000+ Maryland consumers (excluding payment-only data), or 10,000+ if 20%+ of revenue comes from selling personal data, plus a near-ban on selling sensitive data and a data-minimization-first approach. Notably has no broad nonprofit exemption (only insurance-fraud/first-responder nonprofits), no higher-education exemption, and its HIPAA exemption covers PHI data only, not the whole entity. A 2026 amendment restricted selling personal data to government entities involved in immigration enforcement. (Note: many secondary sources incorrectly cite this as §§14-4601 et seq. — that section is an unrelated Forensic Nurse Examiner Training Grant Program provision; the correct MODPA codification is §14-4701 et seq.)

Md. Code, Com. Law §§ 14-4701–14-4714Read statute →

Data Security & Breach Notification · 1

Varies by state
Maryland data breach notification law
MD Breach Notification

Requires reasonable security procedures and practices. Applies regardless of company size whenever you hold covered personal information about a resident of this state.

Md. Code, Com. Law § 14-3501 et seq.Read statute →

Genetic Privacy · 1

Regulates direct-to-consumer genetic testing companies and/or genetic data generally — typically requiring express consent before collecting, using, or disclosing genetic data, and consent (or destruction) requirements for biological samples.

Md. Code, Com. Law §§ 14-4401 et seq. (Subtitle 44)Read statute →

Children & Minors Online Safety · 1

Requires default privacy-protective settings and data protection impact assessments for products likely accessed by minors. (Note: frequently miscited as §14-4751 — the correct codification is Subtitle 48, §§14-4801 et seq.)

Md. Code, Com. Law §§ 14-4801 et seq. (Subtitle 48)Read statute →