Comprehensive statute is in force, but enforcement runs through a general AG office with no dedicated agency, and companion Kids Code faces First-Amendment-style litigation risk seen in peer states.
Primary frameworkMaryland Online Data Privacy Act (MODPA), 2024
Traffic-light rationale — AmberComprehensive statute is in force, but enforcement runs through a general AG office with no dedicated agency, and companion Kids Code faces First-Amendment-style litigation risk seen in peer states.
Sub-modules (5)
Regulator And AuthorityAmber
The Maryland AG holds exclusive enforcement authority over MODPA; there is no separate privacy supervisory authority.
Claims (1):
The Maryland Attorney General has exclusive authority to enforce MODPA, with no dedicated state data protection authority.
Act And InstrumentsGreen
Core instruments are MODPA, the Maryland Kids Code, and the pre-existing PIPA breach-notification statute.
Claims (3):
MODPA was signed May 9, 2024, came into effect October 1, 2025, but does not apply to processing occurring before April 1, 2026.
The Maryland Kids Code (Age-Appropriate Design Code / Online Child Protection Act), effective October 1, 2024, remains fully in effect despite ongoing constitutional litigation of the kind seen against peer-state AADC laws.
Maryland's Personal Information Protection Act (PIPA), Md. Code Ann., Comm. Law §14-3504, is a pre-existing breach-notification statute enforced by the AG, operating independently of MODPA.
Material ScopeAmber
MODPA applies on population/revenue thresholds and carves out government entities and several federally-regulated data types.
Claims (2):
MODPA applies to controllers/processors that controlled or processed personal data of at least 35,000 consumers (excluding payment-transaction-only processing) or at least 10,000 consumers while deriving over 20% of gross revenue from selling personal data.
MODPA excludes Maryland state and local government entities, courts, and businesses/data already subject to the Gramm-Leach-Bliley Act, HIPAA, or FERPA.
Territorial ScopeGreen
MODPA uses an effects-based test keyed to targeting of Maryland residents rather than establishment.
Claims (1):
MODPA applies to individuals/businesses providing products or services targeted to Maryland residents, an effects-based territorial test rather than one requiring in-state establishment.
Regulator Registration And FilingAmber
No general registration/filing regime exists; the AG may compel confidential DPIAs from controllers on request.
Claims (1):
MODPA does not create a general controller registration/filing regime; instead, the AG may request confidential DPIAs from controllers, shielded from disclosure under the Maryland Public Information Act.
Category narrative66 words
Maryland's data-protection landscape is anchored by the Maryland Online Data Privacy Act (MODPA), enacted May 9, 2024 and effective October 1, 2025, enforced exclusively by the Maryland Attorney General with no dedicated privacy regulator. A companion Maryland Kids Code (Age-Appropriate Design Code) and a pre-existing breach-notification statute (Personal Information Protection Act, PIPA) round out the framework. There is no state privacy agency analogous to California's CPPA.
Sources and claims (8)
ConfirmedDataGuidance — The Maryland Attorney General has exclusive authority to enforce MODPA, with no dedicated state data protection authority.observed
ConfirmedDataGuidance — MODPA was signed May 9, 2024, came into effect October 1, 2025, but does not apply to processing occurring before April 1, 2026.observed
ProbableIAPP — The Maryland Kids Code (Age-Appropriate Design Code / Online Child Protection Act), effective October 1, 2024, remains fully in effect despite ongoing constitutional litigation of the kind seen against peer-state AADC laws.observed
ConfirmedMaryland Attorney General — Maryland's Personal Information Protection Act (PIPA), Md. Code Ann., Comm. Law §14-3504, is a pre-existing breach-notification statute enforced by the AG, operating independently of MODPA.observed
ProbableDataGuidance (legacy) — MODPA applies to controllers/processors that controlled or processed personal data of at least 35,000 consumers (excluding payment-transaction-only processing) or at least 10,000 consumers while deriving over 20% of gross revenue from selling personal data.observed
ProbableDataGuidance (legacy) — MODPA excludes Maryland state and local government entities, courts, and businesses/data already subject to the Gramm-Leach-Bliley Act, HIPAA, or FERPA.observed
ProbableDataGuidance (legacy) — MODPA applies to individuals/businesses providing products or services targeted to Maryland residents, an effects-based territorial test rather than one requiring in-state establishment.observed
ProbableDataGuidance (legacy) — MODPA does not create a general controller registration/filing regime; instead, the AG may request confidential DPIAs from controllers, shielded from disclosure under the Maryland Public Information Act.observed
Strong substantive protections exist for sensitive data, but pseudonymisation/anonymisation safe-harbour provisions were not located in available sources.
Primary frameworkMaryland Online Data Privacy Act (MODPA), 2024
Traffic-light rationale — AmberStrong substantive protections exist for sensitive data, but pseudonymisation/anonymisation safe-harbour provisions were not located in available sources.
Sub-modules (4)
Lawful BasesAmber
MODPA substitutes a data-minimization necessity/proportionality test for an enumerated lawful-bases list.
Claims (1):
MODPA requires controllers to limit collection of personal data to what is reasonably necessary and proportionate to provide or maintain the product or service requested by the consumer, functioning as the primary processing-legitimacy standard in place of an enumerated lawful-bases regime.
Consent ThresholdsAmber
Consent must be an 'unambiguous affirmative action'; the minimization-first design leaves few processing activities where consent alone suffices.
Claims (1):
Under MODPA, 'consent' requires an unambiguous affirmative action by the consumer, and the law's minimization-first design leaves consent as a comparatively residual legal basis.
Special CategoriesGreen
Sensitive data is broadly defined and subject to a strict-necessity standard, an absolute sale ban, and health-facility geofencing restrictions.
Claims (3):
MODPA's 'sensitive data' definition includes racial/ethnic origin, religious beliefs, consumer health data, sexual orientation, transgender or non-binary status, citizenship/immigration status, genetic and biometric data, precise geolocation, and personal data known to belong to a child.
Rather than a consent-based model, MODPA bans collection, processing, or sharing of sensitive data unless 'strictly necessary' to provide the requested product/service, and separately prohibits the sale of sensitive data outright under section 14-4607, with no consent exception.
MODPA bans geofencing within 1,750 feet of a mental-health facility or reproductive/sexual-health facility for purposes of identifying, tracking, or targeting consumers in relation to consumer health data.
Pseudonymisation And AnonymisationRed
No MODPA-specific pseudonymisation or anonymisation safe-harbour provision was located in the sources retrieved for this run.
Category narrative43 words
MODPA departs from the GDPR/CCPA-style enumerated-lawful-basis model, instead imposing a substantive data-minimization standard ('reasonably necessary and proportionate') for ordinary personal data and a stricter 'strictly necessary' standard plus an outright sale ban for sensitive data, with no general consent override for sensitive-data sales.
Sources and claims (5)
ConfirmedIAPP — MODPA requires controllers to limit collection of personal data to what is reasonably necessary and proportionate to provide or maintain the product or service requested by the consumer, functioning as the primary processing-legitimacy standard in place of an enumerated lawful-bases regime.observed
ProbableIAPP — Under MODPA, 'consent' requires an unambiguous affirmative action by the consumer, and the law's minimization-first design leaves consent as a comparatively residual legal basis.observed
ConfirmedIAPP — MODPA's 'sensitive data' definition includes racial/ethnic origin, religious beliefs, consumer health data, sexual orientation, transgender or non-binary status, citizenship/immigration status, genetic and biometric data, precise geolocation, and personal data known to belong to a child.observed
ConfirmedIAPP — Rather than a consent-based model, MODPA bans collection, processing, or sharing of sensitive data unless 'strictly necessary' to provide the requested product/service, and separately prohibits the sale of sensitive data outright under section 14-4607, with no consent exception.observed
ConfirmedIAPP — MODPA bans geofencing within 1,750 feet of a mental-health facility or reproductive/sexual-health facility for purposes of identifying, tracking, or targeting consumers in relation to consumer health data.observed
Traffic-light rationale — AmberCore rights are confirmed but the specific response-deadline figure is unverified against primary statutory text in this run.
Sub-modules (5)
Access RightGreen
Consumers may request access to personal data held by a controller.
Claims (1):
MODPA authorizes consumers to exercise rights regarding their personal data and requires controllers to establish a method for consumers to exercise those rights, encompassing access, correction, deletion, and portability.
Rectification And ErasureGreen
Consumers may request correction and deletion of personal data.
Claims (1):
MODPA authorizes consumers to exercise rights regarding their personal data and requires controllers to establish a method for consumers to exercise those rights, encompassing access, correction, deletion, and portability.
Restriction And ObjectionAmber
Consumers may opt out of targeted advertising and sale; MODPA uniquely makes universal opt-out mechanism recognition optional rather than mandatory.
Claims (1):
MODPA describes universal opt-out mechanisms as an alternative to, rather than a mandatory replacement for, a conspicuous 'do not sell' link — the first instance of a state making universal opt-out signal recognition optional.
Data PortabilityGreen
Consumers may obtain a portable copy of their personal data.
Claims (1):
MODPA authorizes consumers to exercise rights regarding their personal data and requires controllers to establish a method for consumers to exercise those rights, encompassing access, correction, deletion, and portability.
Deadlines And Response WindowsRed
Controllers must maintain an appeal process for denied requests; the exact response-window in days was not confirmed in this run's sources.
Claims (2):
MODPA requires controllers to establish an appeal process for consumers regarding controller decisions on rights requests.
The specific statutory number of days within which a Maryland controller must respond to a consumer rights request under MODPA was not confirmed against primary statutory text in this run; comparable Virginia-modeled state laws commonly use a 45-day window with a possible 45-day extension, but this has not been verified as MODPA's exact figure.
Category narrative47 words
MODPA grants Maryland consumers access, correction, deletion, and portability rights, plus opt-outs from targeted advertising, sale, and certain profiling, with a mandatory controller-side appeal process for denied requests. The precise statutory response-window (days) for rights requests could not be confirmed from the sources retrieved in this run.
Sources and claims (4)
ConfirmedDataGuidance — MODPA authorizes consumers to exercise rights regarding their personal data and requires controllers to establish a method for consumers to exercise those rights, encompassing access, correction, deletion, and portability.observed
ConfirmedIAPP — MODPA describes universal opt-out mechanisms as an alternative to, rather than a mandatory replacement for, a conspicuous 'do not sell' link — the first instance of a state making universal opt-out signal recognition optional.observed
ConfirmedDataGuidance (legacy) — MODPA requires controllers to establish an appeal process for consumers regarding controller decisions on rights requests.observed
UncertainIAPP — The specific statutory number of days within which a Maryland controller must respond to a consumer rights request under MODPA was not confirmed against primary statutory text in this run; comparable Virginia-modeled state laws commonly use a 45-day window with a possible 45-day extension, but this has not been verified as MODPA's exact figure.observed
Traffic-light rationale — AmberCore accountability and breach-notification duties are confirmed; DPO and retention-specific provisions are unconfirmed absences.
Sub-modules (7)
Accountability And DpiaGreen
DPIAs are required for heightened-risk processing from October 1, 2025, and are confidential when requested by the AG.
Claims (2):
MODPA requires controllers to conduct data protection impact assessments for processing activities presenting a heightened risk of harm to consumers, applicable to processing occurring on or after October 1, 2025.
DPIAs requested by the Maryland AG under MODPA are confidential and exempt from disclosure under the Maryland Public Information Act.
Dpo RequirementsRed
No MODPA provision mandating a formal Data Protection Officer appointment was located; this is consistent with most US state comprehensive privacy laws.
Claims (1):
No MODPA provision was located requiring controllers to appoint a formal Data Protection Officer; this omission is typical of the US state comprehensive-privacy-law model.
Ropa RequirementsRed
No explicit records-of-processing-activities requirement distinct from the DPIA obligation was located in this run's sources.
Joint Controller ArrangementsGreen
MODPA requires a written, binding controller-processor contract with specified terms.
Claims (1):
MODPA requires controllers and processors to enter into a written, binding contract containing specified data-processing terms whenever a controller engages a processor.
Security MeasuresAmber
MODPA imposes a confidentiality obligation as part of core controller duties.
Claims (1):
MODPA imposes confidentiality obligations on covered businesses as part of its core set of controller duties.
Breach NotificationGreen
PIPA (Md. Code Ann., Comm. Law §14-3504) requires notice to affected residents and the AG following a security breach.
Claims (1):
Maryland's Personal Information Protection Act requires businesses to notify affected Maryland residents and the Attorney General's Identity Theft Unit following a breach of personal information, operating independently of MODPA.
Retention And DisposalRed
No explicit stand-alone retention-limit or disposal-duty provision beyond purpose-based minimization was located in this run's sources.
Category narrative26 words
MODPA imposes DPIA, confidentiality, and processor-contract obligations on controllers, while the separate PIPA statute governs breach notification. No DPO-appointment requirement or explicit retention-limit provision was located.
Sources and claims (6)
ConfirmedDataGuidance — MODPA requires controllers to conduct data protection impact assessments for processing activities presenting a heightened risk of harm to consumers, applicable to processing occurring on or after October 1, 2025.observed
ConfirmedDataGuidance (legacy) — DPIAs requested by the Maryland AG under MODPA are confidential and exempt from disclosure under the Maryland Public Information Act.observed
UncertainDataGuidance — No MODPA provision was located requiring controllers to appoint a formal Data Protection Officer; this omission is typical of the US state comprehensive-privacy-law model.observed
ConfirmedDataGuidance (legacy) — MODPA requires controllers and processors to enter into a written, binding contract containing specified data-processing terms whenever a controller engages a processor.observed
ProbableDataGuidance — MODPA imposes confidentiality obligations on covered businesses as part of its core set of controller duties.observed
ConfirmedMaryland Attorney General — Maryland's Personal Information Protection Act requires businesses to notify affected Maryland residents and the Attorney General's Identity Theft Unit following a breach of personal information, operating independently of MODPA.observed
No comprehensive cross-border transfer regime exists at the Maryland state level; this is an explicit and legitimate absence, not an omission.
Traffic-light rationale — RedNo comprehensive cross-border transfer regime exists at the Maryland state level; this is an explicit and legitimate absence, not an omission.
Sub-modules (6)
Transfer MechanismsRed
No MODPA-specific transfer mechanism provision was located.
Claims (1):
MODPA does not establish a cross-border data-transfer mechanism, adequacy determination process, SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate; such matters remain governed, where applicable, by federal sectoral law.
Adequacy ReceivedRed
Not applicable; US states do not receive adequacy decisions.
Adequacy GrantedRed
Not applicable; Maryland does not grant adequacy decisions.
Sccs And BcrsRed
No state-level SCC/BCR framework exists under MODPA.
Transfer Impact AssessmentRed
No transfer-impact-assessment requirement was located under MODPA.
Data LocalisationRed
No data-localisation mandate was located under MODPA.
Category narrative50 words
MODPA, like other US state comprehensive privacy laws, contains no EU-style cross-border transfer mechanism, adequacy regime, SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate. Such matters for Maryland-resident data remain governed, if at all, by federal sectoral law (e.g., HIPAA, GLBA) or general contract, which fall outside this state-level JID's scope.
Sources and claims (1)
ProbableDataGuidance — MODPA does not establish a cross-border data-transfer mechanism, adequacy determination process, SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate; such matters remain governed, where applicable, by federal sectoral law.observed
Traffic-light rationale — AmberSectoral carve-outs are well-documented; telecoms/eprivacy and insurance-specific overlays were not located in this run.
Sub-modules (7)
Financial Sector OverlayGreen
GLBA-regulated financial institutions and GLBA-covered data are excluded from MODPA.
Claims (1):
MODPA excludes financial institutions and data subject to Title V of the Gramm-Leach-Bliley Act from its scope.
Health Sector OverlayGreen
HIPAA-covered data is excluded from MODPA scope, while MODPA separately regulates non-HIPAA consumer health data with geofencing bans.
Claims (1):
MODPA excludes HIPAA-covered data from its scope while separately regulating non-HIPAA 'consumer health data' with heightened protections including facility geofencing bans.
Telecoms And EprivacyRed
No Maryland-specific telecoms/eprivacy overlay distinct from MODPA was located.
Employment DataRed
No Maryland-specific employment-data privacy overlay was located.
Credit And ScoringGreen
FCRA-covered consumer-reporting-agency activity is excluded from MODPA's sensitive-data sale restrictions.
Claims (1):
MODPA excludes consumer-reporting-agency activity covered by the Fair Credit Reporting Act from its sensitive-data sale restrictions.
EducationGreen
FERPA-covered education records are excluded from MODPA.
Claims (1):
MODPA excludes data covered by the Family Educational Rights and Privacy Act from its scope.
InsuranceRed
No Maryland-specific insurance-sector privacy overlay was located.
Category narrative36 words
MODPA carves out several federally-regulated sectors: GLBA-covered financial institutions, HIPAA-covered health data, FCRA-covered consumer-reporting activity, and FERPA-covered education records are excluded from MODPA's scope, while MODPA itself separately regulates non-HIPAA 'consumer health data' with heightened protections.
Sources and claims (4)
ConfirmedIAPP — MODPA excludes financial institutions and data subject to Title V of the Gramm-Leach-Bliley Act from its scope.observed
ConfirmedIAPP — MODPA excludes HIPAA-covered data from its scope while separately regulating non-HIPAA 'consumer health data' with heightened protections including facility geofencing bans.observed
ConfirmedIAPP — MODPA excludes consumer-reporting-agency activity covered by the Fair Credit Reporting Act from its sensitive-data sale restrictions.observed
ConfirmedIAPP — MODPA excludes data covered by the Family Educational Rights and Privacy Act from its scope.observed
Traffic-light rationale — AmberTargeted-advertising restrictions for minors and UOOM treatment are confirmed; cookie, dark-pattern, and clean-room specifics are unconfirmed.
Sub-modules (6)
Cookies And TrackersRed
No MODPA-specific cookie/tracker consent provision distinct from general consent standards was located.
Dark PatternsAmber
MODPA's consent definition requiring 'unambiguous affirmative action' implicitly disfavours dark-pattern-obtained consent, consistent with peer state laws.
Claims (1):
MODPA defines consent as requiring an 'unambiguous affirmative action,' a standard that implicitly excludes consent obtained via manipulative interface design (dark patterns).
Opt Out SignalsAmber
MODPA treats universal opt-out mechanism recognition as optional rather than mandatory, a notable departure from most peer states.
Claims (1):
MODPA recognizes universal opt-out mechanisms as an optional alternative to a conspicuous 'do not sell' link rather than mandating recognition of such signals.
Clean Rooms And DcrRed
No clean-room or data-collaboration-room-specific provision was located under MODPA.
Cross Context AdvertisingGreen
MODPA bans targeted advertising to consumers a controller knew or should have known are under 18.
Claims (1):
MODPA bans processing personal data for targeted advertising where the controller knew or should have known the consumer is under 18, applying an expanded constructive-knowledge standard.
Direct MarketingRed
No MODPA provision specific to direct-marketing consent/suppression distinct from the general sale/targeted-advertising opt-out was located.
Category narrative35 words
MODPA's commercial-privacy provisions center on an under-18 targeted-advertising ban, an optional (not mandatory) universal opt-out mechanism, and an 'unambiguous affirmative action' consent standard that implicitly disfavours dark-pattern-obtained consent. No cookie-specific or clean-room-specific provisions were located.
Sources and claims (3)
ProbableIAPP — MODPA defines consent as requiring an 'unambiguous affirmative action,' a standard that implicitly excludes consent obtained via manipulative interface design (dark patterns).observed
ConfirmedIAPP — MODPA recognizes universal opt-out mechanisms as an optional alternative to a conspicuous 'do not sell' link rather than mandating recognition of such signals.observed
ConfirmedIAPP — MODPA bans processing personal data for targeted advertising where the controller knew or should have known the consumer is under 18, applying an expanded constructive-knowledge standard.observed
Biometric/genetic protections are confirmed via the sensitive-data regime; ADM transparency, profiling restrictions, and AI risk-assessment mandates are unconfirmed or still proposed.
Primary frameworkMaryland Online Data Privacy Act (MODPA), 2024
Traffic-light rationale — AmberBiometric/genetic protections are confirmed via the sensitive-data regime; ADM transparency, profiling restrictions, and AI risk-assessment mandates are unconfirmed or still proposed.
Sub-modules (6)
Profiling RestrictionsRed
No MODPA provision establishing a general profiling-restriction regime akin to GDPR Art. 22 was located.
Automated Decision Making TransparencyRed
No ADM-transparency/explanation-right provision was located under MODPA.
Ai Risk AssessmentsRed
Maryland is considering, but has not enacted, dedicated AI risk-assessment legislation separate from MODPA.
Claims (1):
Maryland lawmakers are considering AI-specific bills distinct from MODPA, including Senate Bill 827 on chatbot/generative-AI liability and House Bill 956 establishing an AI-implementation workgroup, indicating an emerging but not-yet-comprehensive state AI-governance overlay.
Biometric RegimeGreen
Biometric data is included in MODPA's sensitive-data category, subject to strict-necessity and sale-ban rules.
Claims (1):
MODPA includes biometric and genetic data within its 'sensitive data' definition, subjecting their collection, processing, and sharing to the 'strictly necessary' standard and an outright sale ban.
Genetic DataGreen
Genetic data is likewise included in MODPA's sensitive-data category under the same strict-necessity and sale-ban rules.
Claims (1):
MODPA includes biometric and genetic data within its 'sensitive data' definition, subjecting their collection, processing, and sharing to the 'strictly necessary' standard and an outright sale ban.
State Surveillance CarveoutsRed
No MODPA-specific national-security or state-surveillance carve-out provision was located in this run's sources.
Category narrative48 words
MODPA treats biometric and genetic data as sensitive data subject to strict-necessity and sale-ban rules, but contains no GDPR Art.22-style profiling-restriction or automated-decision-making-transparency regime. Maryland is separately considering (but has not yet enacted as of this run) AI-specific legislation such as chatbot/generative-AI liability and an AI oversight workgroup.
Sources and claims (2)
UncertainDataGuidance — Maryland lawmakers are considering AI-specific bills distinct from MODPA, including Senate Bill 827 on chatbot/generative-AI liability and House Bill 956 establishing an AI-implementation workgroup, indicating an emerging but not-yet-comprehensive state AI-governance overlay.observed
ConfirmedIAPP — MODPA includes biometric and genetic data within its 'sensitive data' definition, subjecting their collection, processing, and sharing to the 'strictly necessary' standard and an outright sale ban.observed
Minor-targeted-advertising and Kids Code protections are confirmed; parental-consent, education-setting, and dependent-adult sub-modules are unconfirmed absences.
Traffic-light rationale — AmberMinor-targeted-advertising and Kids Code protections are confirmed; parental-consent, education-setting, and dependent-adult sub-modules are unconfirmed absences.
Sub-modules (5)
Age VerificationAmber
MODPA uses a 'knew or should have known' constructive-knowledge standard rather than mandating affirmative age verification, though commentators note this could functionally require age-assurance practices.
Claims (1):
MODPA bans processing personal data for targeted advertising and prohibits the sale of personal data belonging to consumers the controller knew or should have known are under 18.
Parental ConsentRed
No MODPA-specific parental-consent mechanism was located; federal COPPA continues to apply concurrently for children under 13.
Claims (1):
MODPA itself does not impose a distinct parental-consent mechanism; federal COPPA continues to apply concurrently for children under 13, and this interaction remains outside MODPA's own text as reviewed.
Minor Profiling BansGreen
MODPA bans targeted advertising and sale of data belonging to consumers known or reasonably known to be minors under 18.
Claims (1):
MODPA bans processing personal data for targeted advertising and prohibits the sale of personal data belonging to consumers the controller knew or should have known are under 18.
Education SettingsRed
No Maryland-specific education-settings privacy rule beyond the general FERPA carve-out was located.
Dependent AdultsRed
No Maryland-specific dependent-adult data-protection provision was located in this run's sources.
Category narrative63 words
Maryland protects minors' data through two instruments: MODPA's ban on targeted advertising/sale for consumers a controller knew or should have known are under 18, and the separate Maryland Kids Code requiring Privacy by Design/Default for products reasonably likely to be accessed by children, in force despite litigation risk. No Maryland-specific parental-consent mechanism distinct from federal COPPA, education-setting rule, or dependent-adult protection was located.
Sources and claims (2)
ConfirmedIAPP — MODPA bans processing personal data for targeted advertising and prohibits the sale of personal data belonging to consumers the controller knew or should have known are under 18.observed
UncertainDataGuidance — MODPA itself does not impose a distinct parental-consent mechanism; federal COPPA continues to apply concurrently for children under 13, and this interaction remains outside MODPA's own text as reviewed.observed
Core enforcement powers and no-private-right-of-action posture are confirmed; regulator funding/capacity data and collective-redress interactions with the general Consumer Protection Act are unconfirmed.
Traffic-light rationale — AmberCore enforcement powers and no-private-right-of-action posture are confirmed; regulator funding/capacity data and collective-redress interactions with the general Consumer Protection Act are unconfirmed.
Sub-modules (6)
Regulator Powers And PenaltiesAmber
AG enforcement runs through Consumer Protection Act unfair/deceptive-trade-practice provisions, with a discretionary 60-day cure right sunsetting in 2027.
Claims (2):
MODPA violations are treated as unfair, abusive, or deceptive trade practices subject to the enforcement and penalty provisions of Title 13 of the Maryland Commercial Law Article (Consumer Protection Act).
The AG may issue a notice of violation triggering a 60-day cure period before bringing an enforcement action, retains discretion over whether to grant the cure opportunity considering factors including violation volume and entity size, and this cure right sunsets in 2027.
Enforcement Activity IndexAmber
Pre-MODPA multistate breach enforcement (e.g., the Inmediata settlement) illustrates the AG's active data-security enforcement track record under PIPA/CPA/HIPAA.
Claims (1):
In 2023, the Maryland AG joined a 33-state settlement with health-data clearinghouse Inmediata over a data exposure affecting 1.5 million consumers (16,423 in Maryland), resolving alleged violations of the Maryland Consumer Protection Act, PIPA, and HIPAA.
Regulator Funding And CapacityRed
No specific budget or headcount data for the AG's privacy-enforcement capacity was located in this run's sources.
Collective Redress And Class ActionsRed
No MODPA-specific collective-redress mechanism was located; its interaction with general Maryland Consumer Protection Act private-action provisions remains unresolved in the sources reviewed.
Claims (1):
No MODPA-specific collective-redress or class-action mechanism was located; whether general Maryland Consumer Protection Act private-action provisions apply to MODPA-predicated claims was not resolved in the sources reviewed.
Private Right Of ActionGreen
MODPA does not create a private right of action; enforcement runs exclusively through the AG.
Claims (1):
MODPA does not create a private cause of action for violations; the Maryland Office of the Attorney General is responsible for enforcement.
Recent Developments 180DAmber
A 2026 amendment strengthened MODPA's sensitive-data and immigration-related protections effective July 1, 2026; further AI-liability and surveillance-pricing bills remain in progress.
Claims (2):
In 2026, Maryland enacted amendments strengthening MODPA's sensitive-data and immigration-enforcement-related protections, effective July 1, 2026.
Additional 2026 Maryland legislative proposals extend the state's data/AI agenda beyond MODPA, including Senate Bill 827 (chatbot/generative-AI liability), House Bill 895 (ban on surveillance-based dynamic pricing in grocery stores), and House Bill 956 (AI-implementation workgroup); their enactment status was not confirmed in this run.
Category narrative52 words
The Maryland AG has exclusive MODPA enforcement authority operating through the state Consumer Protection Act framework, including a discretionary 60-day cure period sunsetting in 2027, and no private right of action. A 2026 amendment strengthened sensitive-data and immigration-related protections effective July 1, 2026, and further AI/pricing-related bills are in the legislative pipeline.
Sources and claims (7)
ConfirmedDataGuidance — MODPA violations are treated as unfair, abusive, or deceptive trade practices subject to the enforcement and penalty provisions of Title 13 of the Maryland Commercial Law Article (Consumer Protection Act).observed
ProbableIAPP — The AG may issue a notice of violation triggering a 60-day cure period before bringing an enforcement action, retains discretion over whether to grant the cure opportunity considering factors including violation volume and entity size, and this cure right sunsets in 2027.observed
ConfirmedMaryland Attorney General — In 2023, the Maryland AG joined a 33-state settlement with health-data clearinghouse Inmediata over a data exposure affecting 1.5 million consumers (16,423 in Maryland), resolving alleged violations of the Maryland Consumer Protection Act, PIPA, and HIPAA.observed
UncertainDataGuidance — No MODPA-specific collective-redress or class-action mechanism was located; whether general Maryland Consumer Protection Act private-action provisions apply to MODPA-predicated claims was not resolved in the sources reviewed.observed
ConfirmedDataGuidance (legacy) — MODPA does not create a private cause of action for violations; the Maryland Office of the Attorney General is responsible for enforcement.observed
ProbableDataGuidance — In 2026, Maryland enacted amendments strengthening MODPA's sensitive-data and immigration-enforcement-related protections, effective July 1, 2026.observed
UncertainDataGuidance — Additional 2026 Maryland legislative proposals extend the state's data/AI agenda beyond MODPA, including Senate Bill 827 (chatbot/generative-AI liability), House Bill 895 (ban on surveillance-based dynamic pricing in grocery stores), and House Bill 956 (AI-implementation workgroup); their enactment status was not confirmed in this run.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for United States – Maryland
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 42 claim(s), 13 source(s) in the cumulative register.
GDPR article map
Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).
regulator_and_framework, lawful_processing_and_special_data, sectoral_watch, children_and_vulnerable_groups, and enforcement_and_redress achieved multi-source T1/T3 coverage (Maryland AG primary docs plus DataGuidance/IAPP secondary analysis). data_subject_rights and controller_processor_duties are substantially covered but rely on T3 secondary commentary for exact response-window and DPO-related details, which could not be verified against primary statutory text in this run. cross_border_and_adequacy is correctly emitted as a legitimate absence (no state-level regime) rather than a silent omission. algorithmic_biometric_and_surveillance_governance and adtech_and_commercial_privacy are partially covered, with ADM-transparency, profiling-restriction, and cookie-specific provisions unconfirmed. No primary Maryland statutory text (mgaleg.maryland.gov) was directly fetchable in this run; all MODPA-specific findings rely on T1 Maryland AG procedural documents plus T3 legal-research/industry secondary sources.
Unresolved questions (5):
What is the exact statutory number of days within which a MODPA controller must respond to a consumer rights request, and is an extension permitted?
Does MODPA impose any explicit data-retention-limit or disposal-duty provision beyond purpose-based minimization?
Has Senate Bill 827 (chatbot/generative-AI liability), House Bill 895 (dynamic-pricing ban), or House Bill 956 (AI workgroup) been enacted as of the run date?
How does the general Maryland Consumer Protection Act's private-action provisions interact with MODPA's stated bar on a private right of action for MODPA-specific violations?
What is the current status and outcome of litigation challenging the Maryland Kids Code, and could it affect its 'fully in effect' status?