{
 "jurisdiction_id": "US-MD",
 "jurisdiction": "United States – Maryland",
 "url": "https://dataprotection.gi/jurisdictions/united-states-maryland/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-06",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 42,
  "sub_modules": 57,
  "source_register": 13
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-maryland/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Comprehensive statute is in force, but enforcement runs through a general AG office with no dedicated agency, and companion Kids Code faces First-Amendment-style litigation risk seen in peer states.",
   "claims": [
    {
     "statement": "The Maryland Attorney General has exclusive authority to enforce MODPA, with no dedicated state data protection authority.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/maryland",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "MODPA was signed May 9, 2024, came into effect October 1, 2025, but does not apply to processing occurring before April 1, 2026.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/maryland",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Maryland Kids Code (Age-Appropriate Design Code / Online Child Protection Act), effective October 1, 2024, remains fully in effect despite ongoing constitutional litigation of the kind seen against peer-state AADC laws.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-view-from-dc-youth-privacy-in-california-rises-again-kind-of",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Maryland's Personal Information Protection Act (PIPA), Md. Code Ann., Comm. Law §14-3504, is a pre-existing breach-notification statute enforced by the AG, operating independently of MODPA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Maryland Attorney General",
     "source_url": "https://www.marylandattorneygeneral.gov/ID%20Theft%20Breach%20Notices/2023/ITU-374098.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "MODPA applies to controllers/processors that controlled or processed personal data of at least 35,000 consumers (excluding payment-transaction-only processing) or at least 10,000 consumers while deriving over 20% of gross revenue from selling personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance (legacy)",
     "source_url": "https://legacy.dataguidance.com/opinion/maryland-online-data-privacy-act-2024-gains-traction",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "MODPA excludes Maryland state and local government entities, courts, and businesses/data already subject to the Gramm-Leach-Bliley Act, HIPAA, or FERPA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance (legacy)",
     "source_url": "https://legacy.dataguidance.com/opinion/maryland-online-data-privacy-act-2024-gains-traction",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "MODPA applies to individuals/businesses providing products or services targeted to Maryland residents, an effects-based territorial test rather than one requiring in-state establishment.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance (legacy)",
     "source_url": "https://legacy.dataguidance.com/opinion/maryland-online-data-privacy-act-2024-gains-traction",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "MODPA does not create a general controller registration/filing regime; instead, the AG may request confidential DPIAs from controllers, shielded from disclosure under the Maryland Public Information Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance (legacy)",
     "source_url": "https://legacy.dataguidance.com/opinion/maryland-online-data-privacy-act-2024-gains-traction",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-maryland/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Strong substantive protections exist for sensitive data, but pseudonymisation/anonymisation safe-harbour provisions were not located in available sources.",
   "claims": [
    {
     "statement": "MODPA requires controllers to limit collection of personal data to what is reasonably necessary and proportionate to provide or maintain the product or service requested by the consumer, functioning as the primary processing-legitimacy standard in place of an enumerated lawful-bases regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/unpacking-the-shift-towards-substantive-data-minimization-rules-in-proposed-legislation",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Under MODPA, 'consent' requires an unambiguous affirmative action by the consumer, and the law's minimization-first design leaves consent as a comparatively residual legal basis.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-view-from-dc-will-maryland-end-the-era-of-notice-and-choice",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "MODPA's 'sensitive data' definition includes racial/ethnic origin, religious beliefs, consumer health data, sexual orientation, transgender or non-binary status, citizenship/immigration status, genetic and biometric data, precise geolocation, and personal data known to belong to a child.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-case-study-in-privacy-operations-the-maryland-spi-rule",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Rather than a consent-based model, MODPA bans collection, processing, or sharing of sensitive data unless 'strictly necessary' to provide the requested product/service, and separately prohibits the sale of sensitive data outright under section 14-4607, with no consent exception.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-view-from-dc-privacy-law-flirts-with-its-ban-it-era",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "MODPA bans geofencing within 1,750 feet of a mental-health facility or reproductive/sexual-health facility for purposes of identifying, tracking, or targeting consumers in relation to consumer health data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-view-from-dc-privacy-law-flirts-with-its-ban-it-era",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-maryland/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Core rights are confirmed but the specific response-deadline figure is unverified against primary statutory text in this run.",
   "claims": [
    {
     "statement": "MODPA authorizes consumers to exercise rights regarding their personal data and requires controllers to establish a method for consumers to exercise those rights, encompassing access, correction, deletion, and portability.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/maryland-house-bill-establishing-online-data-privacy-1",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "MODPA describes universal opt-out mechanisms as an alternative to, rather than a mandatory replacement for, a conspicuous 'do not sell' link — the first instance of a state making universal opt-out signal recognition optional.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/maryland-adds-new-dimension-to-us-comprehensive-state-privacy-law-patchwork",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "MODPA requires controllers to establish an appeal process for consumers regarding controller decisions on rights requests.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance (legacy)",
     "source_url": "https://legacy.dataguidance.com/opinion/maryland-online-data-privacy-act-2024-gains-traction",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The specific statutory number of days within which a Maryland controller must respond to a consumer rights request under MODPA was not confirmed against primary statutory text in this run; comparable Virginia-modeled state laws commonly use a 45-day window with a possible 45-day extension, but this has not been verified as MODPA's exact figure.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-5-operational-impacts-of-cacpa-part-3-responding-to-consumers-personal-information-access-requests",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-maryland/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Core accountability and breach-notification duties are confirmed; DPO and retention-specific provisions are unconfirmed absences.",
   "claims": [
    {
     "statement": "MODPA requires controllers to conduct data protection impact assessments for processing activities presenting a heightened risk of harm to consumers, applicable to processing occurring on or after October 1, 2025.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/maryland",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "DPIAs requested by the Maryland AG under MODPA are confidential and exempt from disclosure under the Maryland Public Information Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance (legacy)",
     "source_url": "https://legacy.dataguidance.com/opinion/maryland-online-data-privacy-act-2024-gains-traction",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No MODPA provision was located requiring controllers to appoint a formal Data Protection Officer; this omission is typical of the US state comprehensive-privacy-law model.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/maryland",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "MODPA requires controllers and processors to enter into a written, binding contract containing specified data-processing terms whenever a controller engages a processor.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance (legacy)",
     "source_url": "https://legacy.dataguidance.com/opinion/maryland-online-data-privacy-act-2024-gains-traction",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "MODPA imposes confidentiality obligations on covered businesses as part of its core set of controller duties.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/maryland",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Maryland's Personal Information Protection Act requires businesses to notify affected Maryland residents and the Attorney General's Identity Theft Unit following a breach of personal information, operating independently of MODPA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Maryland Attorney General",
     "source_url": "https://www.marylandattorneygeneral.gov/ID%20Theft%20Breach%20Notices/2023/ITU-374098.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "red",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-maryland/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "No comprehensive cross-border transfer regime exists at the Maryland state level; this is an explicit and legitimate absence, not an omission.",
   "claims": [
    {
     "statement": "MODPA does not establish a cross-border data-transfer mechanism, adequacy determination process, SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate; such matters remain governed, where applicable, by federal sectoral law.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/maryland",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-maryland/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Sectoral carve-outs are well-documented; telecoms/eprivacy and insurance-specific overlays were not located in this run.",
   "claims": [
    {
     "statement": "MODPA excludes financial institutions and data subject to Title V of the Gramm-Leach-Bliley Act from its scope.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-view-from-dc-privacy-law-flirts-with-its-ban-it-era",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "MODPA excludes HIPAA-covered data from its scope while separately regulating non-HIPAA 'consumer health data' with heightened protections including facility geofencing bans.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-view-from-dc-privacy-law-flirts-with-its-ban-it-era",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "MODPA excludes consumer-reporting-agency activity covered by the Fair Credit Reporting Act from its sensitive-data sale restrictions.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-view-from-dc-privacy-law-flirts-with-its-ban-it-era",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "MODPA excludes data covered by the Family Educational Rights and Privacy Act from its scope.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-view-from-dc-privacy-law-flirts-with-its-ban-it-era",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-maryland/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Targeted-advertising restrictions for minors and UOOM treatment are confirmed; cookie, dark-pattern, and clean-room specifics are unconfirmed.",
   "claims": [
    {
     "statement": "MODPA defines consent as requiring an 'unambiguous affirmative action,' a standard that implicitly excludes consent obtained via manipulative interface design (dark patterns).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-view-from-dc-will-maryland-end-the-era-of-notice-and-choice",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "MODPA recognizes universal opt-out mechanisms as an optional alternative to a conspicuous 'do not sell' link rather than mandating recognition of such signals.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/maryland-adds-new-dimension-to-us-comprehensive-state-privacy-law-patchwork",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "MODPA bans processing personal data for targeted advertising where the controller knew or should have known the consumer is under 18, applying an expanded constructive-knowledge standard.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-view-from-dc-privacy-law-flirts-with-its-ban-it-era",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-maryland/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Biometric/genetic protections are confirmed via the sensitive-data regime; ADM transparency, profiling restrictions, and AI risk-assessment mandates are unconfirmed or still proposed.",
   "claims": [
    {
     "statement": "Maryland lawmakers are considering AI-specific bills distinct from MODPA, including Senate Bill 827 on chatbot/generative-AI liability and House Bill 956 establishing an AI-implementation workgroup, indicating an emerging but not-yet-comprehensive state AI-governance overlay.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/maryland",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "MODPA includes biometric and genetic data within its 'sensitive data' definition, subjecting their collection, processing, and sharing to the 'strictly necessary' standard and an outright sale ban.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-case-study-in-privacy-operations-the-maryland-spi-rule",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-maryland/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Minor-targeted-advertising and Kids Code protections are confirmed; parental-consent, education-setting, and dependent-adult sub-modules are unconfirmed absences.",
   "claims": [
    {
     "statement": "MODPA bans processing personal data for targeted advertising and prohibits the sale of personal data belonging to consumers the controller knew or should have known are under 18.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/maryland-adds-new-dimension-to-us-comprehensive-state-privacy-law-patchwork",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "MODPA itself does not impose a distinct parental-consent mechanism; federal COPPA continues to apply concurrently for children under 13, and this interaction remains outside MODPA's own text as reviewed.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/maryland",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-maryland/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Core enforcement powers and no-private-right-of-action posture are confirmed; regulator funding/capacity data and collective-redress interactions with the general Consumer Protection Act are unconfirmed.",
   "claims": [
    {
     "statement": "MODPA violations are treated as unfair, abusive, or deceptive trade practices subject to the enforcement and penalty provisions of Title 13 of the Maryland Commercial Law Article (Consumer Protection Act).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/maryland",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The AG may issue a notice of violation triggering a 60-day cure period before bringing an enforcement action, retains discretion over whether to grant the cure opportunity considering factors including violation volume and entity size, and this cure right sunsets in 2027.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/maryland-adds-new-dimension-to-us-comprehensive-state-privacy-law-patchwork",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "In 2023, the Maryland AG joined a 33-state settlement with health-data clearinghouse Inmediata over a data exposure affecting 1.5 million consumers (16,423 in Maryland), resolving alleged violations of the Maryland Consumer Protection Act, PIPA, and HIPAA.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Maryland Attorney General",
     "source_url": "https://www.marylandattorneygeneral.gov/press/2023/101823a.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No MODPA-specific collective-redress or class-action mechanism was located; whether general Maryland Consumer Protection Act private-action provisions apply to MODPA-predicated claims was not resolved in the sources reviewed.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/maryland",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "MODPA does not create a private cause of action for violations; the Maryland Office of the Attorney General is responsible for enforcement.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance (legacy)",
     "source_url": "https://legacy.dataguidance.com/opinion/maryland-online-data-privacy-act-2024-gains-traction",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "In 2026, Maryland enacted amendments strengthening MODPA's sensitive-data and immigration-enforcement-related protections, effective July 1, 2026.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/maryland-data-privacy-act-strengthening-protections",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Additional 2026 Maryland legislative proposals extend the state's data/AI agenda beyond MODPA, including Senate Bill 827 (chatbot/generative-AI liability), House Bill 895 (ban on surveillance-based dynamic pricing in grocery stores), and House Bill 956 (AI-implementation workgroup); their enactment status was not confirmed in this run.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/maryland",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  }
 ]
}