State Guide
Maryland Privacy & Data Security Laws
Every statute below can apply to a business handling Maryland residents' data, depending on your revenue, the number of Maryland consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
One of the strictest state laws: no revenue threshold. Applies at 35,000+ Maryland consumers (excluding payment-only data), or 10,000+ if 20%+ of revenue comes from selling personal data, plus a near-ban on selling sensitive data and a data-minimization-first approach. Notably has no broad nonprofit exemption (only insurance-fraud/first-responder nonprofits), no higher-education exemption, and its HIPAA exemption covers PHI data only, not the whole entity. A 2026 amendment restricted selling personal data to government entities involved in immigration enforcement. (Note: many secondary sources incorrectly cite this as §§14-4601 et seq. — that section is an unrelated Forensic Nurse Examiner Training Grant Program provision; the correct MODPA codification is §14-4701 et seq.)
Data Security & Breach Notification · 1
Requires reasonable security procedures and practices. Applies regardless of company size whenever you hold covered personal information about a resident of this state.
Genetic Privacy · 1
Regulates direct-to-consumer genetic testing companies and/or genetic data generally — typically requiring express consent before collecting, using, or disclosing genetic data, and consent (or destruction) requirements for biological samples.
Children & Minors Online Safety · 1
Requires default privacy-protective settings and data protection impact assessments for products likely accessed by minors. (Note: frequently miscited as §14-4751 — the correct codification is Subtitle 48, §§14-4801 et seq.)