Most US state privacy laws follow a familiar pattern: give consumers the right to opt out, post a privacy notice, honor requests. Maryland's law breaks that pattern. The Maryland Online Data Privacy Act (MODPA) sets harder limits — restricting what you're allowed to collect in the first place and banning the sale of sensitive data entirely. For website owners, that makes it one of the more demanding US laws to get right.
Key takeaways
- MODPA took effect October 1, 2025; enforcement began April 1, 2026.
- It applies at a lower threshold (35,000 consumers) than most states, so it reaches smaller businesses.
- Its defining feature is strict data minimization — you may only collect what's reasonably necessary, regardless of consent.
- Selling sensitive data is prohibited outright, and sensitive data needs opt-in consent.
What MODPA is
The Maryland Online Data Privacy Act was signed into law on May 9, 2024, making Maryland the 18th US state with a comprehensive consumer privacy law. It took effect on October 1, 2025, but by its own terms did not apply to personal data processing activities before April 1, 2026 — giving businesses a short transition window. Enforcement is handled by the Maryland Attorney General.
What sets it apart is its philosophy. Where most state laws put the burden on consumers to opt out of data practices, MODPA puts the burden on businesses to limit their practices up front — closer in spirit to the EU's data-minimization principle than to the typical American opt-out model.
Who it applies to
MODPA applies to anyone who conducts business in Maryland or provides products or services targeted to Maryland residents and, during the prior calendar year, either:
- controlled or processed the personal data of at least 35,000 Maryland consumers (excluding data used solely for payment transactions), or
- controlled or processed the personal data of at least 10,000 consumers and derived more than 20% of gross revenue from selling personal data.
The 35,000 threshold is notably lower than the 100,000 used by several other states, which means MODPA can apply to smaller businesses than you might assume from other state laws.
What makes it stricter
Hard data minimization
This is MODPA's signature. Controllers may only collect personal data that is reasonably necessary and proportionate to provide the specific product or service the consumer requested. Crucially, this limit applies regardless of consent — you cannot simply ask the consumer to agree to broader collection. It flips the usual model: instead of "collect what you can justify with consent," it's "collect only what the service genuinely requires."
Sensitive data: no sale, strict necessity
MODPA prohibits the sale of sensitive data entirely — not "with consent," but at all. And sensitive data may only be processed when strictly necessary to provide a product or service the consumer asked for. Maryland also defines sensitive and consumer-health data more broadly than many states.
What it requires of websites
For a website operator in scope, the practical obligations include:
- Honor opt-outs of targeted advertising, the sale of personal data, and profiling — with a clear, conspicuous mechanism on your site.
- Recognize universal opt-out signals such as Global Privacy Control, treating them as a valid opt-out.
- Obtain opt-in consent before processing sensitive data, and never sell it.
- Provide a clear privacy notice and respond to consumer rights requests (access, correction, deletion, portability) within 45 days.
- Conduct data protection assessments for higher-risk processing.
How ConsentPixel helps
ConsentPixel's consent engine handles the browser-level mechanics MODPA depends on: it blocks trackers until the appropriate consent or opt-out state is established, recognizes Global Privacy Control and other universal opt-out signals, gates sensitive-data tracking behind opt-in, and logs each decision so you can demonstrate what happened. Coverage extends across every page, so an opt-out isn't honored on the homepage while trackers fire freely on a product page.
One honest note: MODPA's data-minimization and sensitive-data-sale limits are operational obligations for your whole business — they govern what you collect and how you handle it everywhere, not just what fires in the browser. ConsentPixel supports your MODPA readiness on the consent and tracking side; the broader minimization and data-handling practices are organizational steps your business owns. It sits alongside ConsentPixel's other US-state coverage as part of a single consent layer.
Frequently asked questions
MODPA is Maryland's comprehensive consumer privacy law, signed in May 2024 and effective October 1, 2025, with enforcement beginning April 1, 2026. It made Maryland the 18th US state with a comprehensive privacy law, and it is considered one of the strictest — notably for its hard data-minimization limits and its outright ban on selling sensitive data.
MODPA applies to businesses that operate in Maryland or target Maryland residents and that, in the prior year, processed the personal data of at least 35,000 Maryland consumers, or at least 10,000 consumers if more than 20 percent of gross revenue comes from selling personal data. The 35,000 threshold is lower than most other state laws, so it can apply to smaller businesses.
Two things stand out. First, strict data minimization: controllers may only collect personal data that is reasonably necessary to provide the product or service the consumer requested — a limit that applies regardless of consent. Second, sensitive data: it may only be processed when strictly necessary, and it may not be sold under any circumstances. Most other state laws rely more heavily on consumer opt-outs rather than these hard limits.
MODPA requires honoring opt-outs of targeted advertising, sale, and profiling, recognizing universal opt-out mechanisms (like Global Privacy Control), and obtaining opt-in consent before processing sensitive data. In practice that means a consent and preference mechanism on your site that can capture these choices, recognize browser opt-out signals, and block tracking accordingly.
ConsentPixel's consent engine covers the core MODPA mechanics — blocking trackers until consent, honoring opt-out and Global Privacy Control signals, and logging decisions. The data-minimization and sensitive-data-sale limits are operational obligations for your business beyond the consent layer, so ConsentPixel supports MODPA readiness rather than being sufficient for full compliance on its own.
See where your site stands
ConsentPixel blocks trackers until consent, monitors every page, and logs every decision — from a single pixel. Find out where your site stands in about 10 seconds.
Scan your site free