🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-MD · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 13 sources retrieved model claude-sonnet-5 ·

United States – Maryland

US-MD schema gdpri-v2 trajectory: not recordedhybrid regimeoverlaps: FIM, WPM, AIC

Last updated · 10 categories · 42 claims · 13 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
42Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive statute is in force, but enforcement runs through a general AG office with no dedicated agency, and companion Kids Code faces First-Amendment-style litigation risk seen in peer states.

Primary frameworkMaryland Online Data Privacy Act (MODPA), 2024
Traffic-light rationale — AmberComprehensive statute is in force, but enforcement runs through a general AG office with no dedicated agency, and companion Kids Code faces First-Amendment-style litigation risk seen in peer states.

Sub-modules (5)

Regulator And AuthorityAmber

The Maryland AG holds exclusive enforcement authority over MODPA; there is no separate privacy supervisory authority.

Claims (1):

  • The Maryland Attorney General has exclusive authority to enforce MODPA, with no dedicated state data protection authority.

Act And InstrumentsGreen

Core instruments are MODPA, the Maryland Kids Code, and the pre-existing PIPA breach-notification statute.

Claims (3):

  • MODPA was signed May 9, 2024, came into effect October 1, 2025, but does not apply to processing occurring before April 1, 2026.
  • The Maryland Kids Code (Age-Appropriate Design Code / Online Child Protection Act), effective October 1, 2024, remains fully in effect despite ongoing constitutional litigation of the kind seen against peer-state AADC laws.
  • Maryland's Personal Information Protection Act (PIPA), Md. Code Ann., Comm. Law §14-3504, is a pre-existing breach-notification statute enforced by the AG, operating independently of MODPA.

Material ScopeAmber

MODPA applies on population/revenue thresholds and carves out government entities and several federally-regulated data types.

Claims (2):

  • MODPA applies to controllers/processors that controlled or processed personal data of at least 35,000 consumers (excluding payment-transaction-only processing) or at least 10,000 consumers while deriving over 20% of gross revenue from selling personal data.
  • MODPA excludes Maryland state and local government entities, courts, and businesses/data already subject to the Gramm-Leach-Bliley Act, HIPAA, or FERPA.

Territorial ScopeGreen

MODPA uses an effects-based test keyed to targeting of Maryland residents rather than establishment.

Claims (1):

  • MODPA applies to individuals/businesses providing products or services targeted to Maryland residents, an effects-based territorial test rather than one requiring in-state establishment.

Regulator Registration And FilingAmber

No general registration/filing regime exists; the AG may compel confidential DPIAs from controllers on request.

Claims (1):

  • MODPA does not create a general controller registration/filing regime; instead, the AG may request confidential DPIAs from controllers, shielded from disclosure under the Maryland Public Information Act.
Category narrative66 words

Maryland's data-protection landscape is anchored by the Maryland Online Data Privacy Act (MODPA), enacted May 9, 2024 and effective October 1, 2025, enforced exclusively by the Maryland Attorney General with no dedicated privacy regulator. A companion Maryland Kids Code (Age-Appropriate Design Code) and a pre-existing breach-notification statute (Personal Information Protection Act, PIPA) round out the framework. There is no state privacy agency analogous to California's CPPA.

Sources and claims (8)
  1. ConfirmedDataGuidanceThe Maryland Attorney General has exclusive authority to enforce MODPA, with no dedicated state data protection authority.observed
  2. ConfirmedDataGuidanceMODPA was signed May 9, 2024, came into effect October 1, 2025, but does not apply to processing occurring before April 1, 2026.observed
  3. ProbableIAPPThe Maryland Kids Code (Age-Appropriate Design Code / Online Child Protection Act), effective October 1, 2024, remains fully in effect despite ongoing constitutional litigation of the kind seen against peer-state AADC laws.observed
  4. ConfirmedMaryland Attorney GeneralMaryland's Personal Information Protection Act (PIPA), Md. Code Ann., Comm. Law §14-3504, is a pre-existing breach-notification statute enforced by the AG, operating independently of MODPA.observed
  5. ProbableDataGuidance (legacy)MODPA applies to controllers/processors that controlled or processed personal data of at least 35,000 consumers (excluding payment-transaction-only processing) or at least 10,000 consumers while deriving over 20% of gross revenue from selling personal data.observed
  6. ProbableDataGuidance (legacy)MODPA excludes Maryland state and local government entities, courts, and businesses/data already subject to the Gramm-Leach-Bliley Act, HIPAA, or FERPA.observed
  7. ProbableDataGuidance (legacy)MODPA applies to individuals/businesses providing products or services targeted to Maryland residents, an effects-based territorial test rather than one requiring in-state establishment.observed
  8. ProbableDataGuidance (legacy)MODPA does not create a general controller registration/filing regime; instead, the AG may request confidential DPIAs from controllers, shielded from disclosure under the Maryland Public Information Act.observed

#

Strong substantive protections exist for sensitive data, but pseudonymisation/anonymisation safe-harbour provisions were not located in available sources.

Primary frameworkMaryland Online Data Privacy Act (MODPA), 2024
Traffic-light rationale — AmberStrong substantive protections exist for sensitive data, but pseudonymisation/anonymisation safe-harbour provisions were not located in available sources.

Sub-modules (4)

Lawful BasesAmber

MODPA substitutes a data-minimization necessity/proportionality test for an enumerated lawful-bases list.

Claims (1):

  • MODPA requires controllers to limit collection of personal data to what is reasonably necessary and proportionate to provide or maintain the product or service requested by the consumer, functioning as the primary processing-legitimacy standard in place of an enumerated lawful-bases regime.

Special CategoriesGreen

Sensitive data is broadly defined and subject to a strict-necessity standard, an absolute sale ban, and health-facility geofencing restrictions.

Claims (3):

  • MODPA's 'sensitive data' definition includes racial/ethnic origin, religious beliefs, consumer health data, sexual orientation, transgender or non-binary status, citizenship/immigration status, genetic and biometric data, precise geolocation, and personal data known to belong to a child.
  • Rather than a consent-based model, MODPA bans collection, processing, or sharing of sensitive data unless 'strictly necessary' to provide the requested product/service, and separately prohibits the sale of sensitive data outright under section 14-4607, with no consent exception.
  • MODPA bans geofencing within 1,750 feet of a mental-health facility or reproductive/sexual-health facility for purposes of identifying, tracking, or targeting consumers in relation to consumer health data.

Pseudonymisation And AnonymisationRed

No MODPA-specific pseudonymisation or anonymisation safe-harbour provision was located in the sources retrieved for this run.

Category narrative43 words

MODPA departs from the GDPR/CCPA-style enumerated-lawful-basis model, instead imposing a substantive data-minimization standard ('reasonably necessary and proportionate') for ordinary personal data and a stricter 'strictly necessary' standard plus an outright sale ban for sensitive data, with no general consent override for sensitive-data sales.

Sources and claims (5)
  1. ConfirmedIAPPMODPA requires controllers to limit collection of personal data to what is reasonably necessary and proportionate to provide or maintain the product or service requested by the consumer, functioning as the primary processing-legitimacy standard in place of an enumerated lawful-bases regime.observed
  2. ProbableIAPPUnder MODPA, 'consent' requires an unambiguous affirmative action by the consumer, and the law's minimization-first design leaves consent as a comparatively residual legal basis.observed
  3. ConfirmedIAPPMODPA's 'sensitive data' definition includes racial/ethnic origin, religious beliefs, consumer health data, sexual orientation, transgender or non-binary status, citizenship/immigration status, genetic and biometric data, precise geolocation, and personal data known to belong to a child.observed
  4. ConfirmedIAPPRather than a consent-based model, MODPA bans collection, processing, or sharing of sensitive data unless 'strictly necessary' to provide the requested product/service, and separately prohibits the sale of sensitive data outright under section 14-4607, with no consent exception.observed
  5. ConfirmedIAPPMODPA bans geofencing within 1,750 feet of a mental-health facility or reproductive/sexual-health facility for purposes of identifying, tracking, or targeting consumers in relation to consumer health data.observed

#

Core rights are confirmed but the specific response-deadline figure is unverified against primary statutory text in this run.

Primary frameworkMaryland Online Data Privacy Act (MODPA), 2024
Traffic-light rationale — AmberCore rights are confirmed but the specific response-deadline figure is unverified against primary statutory text in this run.

Sub-modules (5)

Access RightGreen

Consumers may request access to personal data held by a controller.

Claims (1):

  • MODPA authorizes consumers to exercise rights regarding their personal data and requires controllers to establish a method for consumers to exercise those rights, encompassing access, correction, deletion, and portability.

Rectification And ErasureGreen

Consumers may request correction and deletion of personal data.

Claims (1):

  • MODPA authorizes consumers to exercise rights regarding their personal data and requires controllers to establish a method for consumers to exercise those rights, encompassing access, correction, deletion, and portability.

Restriction And ObjectionAmber

Consumers may opt out of targeted advertising and sale; MODPA uniquely makes universal opt-out mechanism recognition optional rather than mandatory.

Claims (1):

  • MODPA describes universal opt-out mechanisms as an alternative to, rather than a mandatory replacement for, a conspicuous 'do not sell' link — the first instance of a state making universal opt-out signal recognition optional.

Data PortabilityGreen

Consumers may obtain a portable copy of their personal data.

Claims (1):

  • MODPA authorizes consumers to exercise rights regarding their personal data and requires controllers to establish a method for consumers to exercise those rights, encompassing access, correction, deletion, and portability.

Deadlines And Response WindowsRed

Controllers must maintain an appeal process for denied requests; the exact response-window in days was not confirmed in this run's sources.

Claims (2):

  • MODPA requires controllers to establish an appeal process for consumers regarding controller decisions on rights requests.
  • The specific statutory number of days within which a Maryland controller must respond to a consumer rights request under MODPA was not confirmed against primary statutory text in this run; comparable Virginia-modeled state laws commonly use a 45-day window with a possible 45-day extension, but this has not been verified as MODPA's exact figure.
Category narrative47 words

MODPA grants Maryland consumers access, correction, deletion, and portability rights, plus opt-outs from targeted advertising, sale, and certain profiling, with a mandatory controller-side appeal process for denied requests. The precise statutory response-window (days) for rights requests could not be confirmed from the sources retrieved in this run.

Sources and claims (4)
  1. ConfirmedDataGuidanceMODPA authorizes consumers to exercise rights regarding their personal data and requires controllers to establish a method for consumers to exercise those rights, encompassing access, correction, deletion, and portability.observed
  2. ConfirmedIAPPMODPA describes universal opt-out mechanisms as an alternative to, rather than a mandatory replacement for, a conspicuous 'do not sell' link — the first instance of a state making universal opt-out signal recognition optional.observed
  3. ConfirmedDataGuidance (legacy)MODPA requires controllers to establish an appeal process for consumers regarding controller decisions on rights requests.observed
  4. UncertainIAPPThe specific statutory number of days within which a Maryland controller must respond to a consumer rights request under MODPA was not confirmed against primary statutory text in this run; comparable Virginia-modeled state laws commonly use a 45-day window with a possible 45-day extension, but this has not been verified as MODPA's exact figure.observed

#

Core accountability and breach-notification duties are confirmed; DPO and retention-specific provisions are unconfirmed absences.

Primary frameworkMaryland Online Data Privacy Act (MODPA); Maryland Personal Information Protection Act (PIPA)
Traffic-light rationale — AmberCore accountability and breach-notification duties are confirmed; DPO and retention-specific provisions are unconfirmed absences.

Sub-modules (7)

Accountability And DpiaGreen

DPIAs are required for heightened-risk processing from October 1, 2025, and are confidential when requested by the AG.

Claims (2):

  • MODPA requires controllers to conduct data protection impact assessments for processing activities presenting a heightened risk of harm to consumers, applicable to processing occurring on or after October 1, 2025.
  • DPIAs requested by the Maryland AG under MODPA are confidential and exempt from disclosure under the Maryland Public Information Act.

Dpo RequirementsRed

No MODPA provision mandating a formal Data Protection Officer appointment was located; this is consistent with most US state comprehensive privacy laws.

Claims (1):

  • No MODPA provision was located requiring controllers to appoint a formal Data Protection Officer; this omission is typical of the US state comprehensive-privacy-law model.

Ropa RequirementsRed

No explicit records-of-processing-activities requirement distinct from the DPIA obligation was located in this run's sources.

Joint Controller ArrangementsGreen

MODPA requires a written, binding controller-processor contract with specified terms.

Claims (1):

  • MODPA requires controllers and processors to enter into a written, binding contract containing specified data-processing terms whenever a controller engages a processor.

Security MeasuresAmber

MODPA imposes a confidentiality obligation as part of core controller duties.

Claims (1):

  • MODPA imposes confidentiality obligations on covered businesses as part of its core set of controller duties.

Breach NotificationGreen

PIPA (Md. Code Ann., Comm. Law §14-3504) requires notice to affected residents and the AG following a security breach.

Claims (1):

  • Maryland's Personal Information Protection Act requires businesses to notify affected Maryland residents and the Attorney General's Identity Theft Unit following a breach of personal information, operating independently of MODPA.

Retention And DisposalRed

No explicit stand-alone retention-limit or disposal-duty provision beyond purpose-based minimization was located in this run's sources.

Category narrative26 words

MODPA imposes DPIA, confidentiality, and processor-contract obligations on controllers, while the separate PIPA statute governs breach notification. No DPO-appointment requirement or explicit retention-limit provision was located.

Sources and claims (6)
  1. ConfirmedDataGuidanceMODPA requires controllers to conduct data protection impact assessments for processing activities presenting a heightened risk of harm to consumers, applicable to processing occurring on or after October 1, 2025.observed
  2. ConfirmedDataGuidance (legacy)DPIAs requested by the Maryland AG under MODPA are confidential and exempt from disclosure under the Maryland Public Information Act.observed
  3. UncertainDataGuidanceNo MODPA provision was located requiring controllers to appoint a formal Data Protection Officer; this omission is typical of the US state comprehensive-privacy-law model.observed
  4. ConfirmedDataGuidance (legacy)MODPA requires controllers and processors to enter into a written, binding contract containing specified data-processing terms whenever a controller engages a processor.observed
  5. ProbableDataGuidanceMODPA imposes confidentiality obligations on covered businesses as part of its core set of controller duties.observed
  6. ConfirmedMaryland Attorney GeneralMaryland's Personal Information Protection Act requires businesses to notify affected Maryland residents and the Attorney General's Identity Theft Unit following a breach of personal information, operating independently of MODPA.observed

#

No comprehensive cross-border transfer regime exists at the Maryland state level; this is an explicit and legitimate absence, not an omission.

Traffic-light rationale — RedNo comprehensive cross-border transfer regime exists at the Maryland state level; this is an explicit and legitimate absence, not an omission.

Sub-modules (6)

Transfer MechanismsRed

No MODPA-specific transfer mechanism provision was located.

Claims (1):

  • MODPA does not establish a cross-border data-transfer mechanism, adequacy determination process, SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate; such matters remain governed, where applicable, by federal sectoral law.

Adequacy ReceivedRed

Not applicable; US states do not receive adequacy decisions.

Adequacy GrantedRed

Not applicable; Maryland does not grant adequacy decisions.

Sccs And BcrsRed

No state-level SCC/BCR framework exists under MODPA.

Transfer Impact AssessmentRed

No transfer-impact-assessment requirement was located under MODPA.

Data LocalisationRed

No data-localisation mandate was located under MODPA.

Category narrative50 words

MODPA, like other US state comprehensive privacy laws, contains no EU-style cross-border transfer mechanism, adequacy regime, SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate. Such matters for Maryland-resident data remain governed, if at all, by federal sectoral law (e.g., HIPAA, GLBA) or general contract, which fall outside this state-level JID's scope.

Sources and claims (1)
  1. ProbableDataGuidanceMODPA does not establish a cross-border data-transfer mechanism, adequacy determination process, SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate; such matters remain governed, where applicable, by federal sectoral law.observed

#

Sectoral carve-outs are well-documented; telecoms/eprivacy and insurance-specific overlays were not located in this run.

Primary frameworkMaryland Online Data Privacy Act (MODPA), 2024
Traffic-light rationale — AmberSectoral carve-outs are well-documented; telecoms/eprivacy and insurance-specific overlays were not located in this run.

Sub-modules (7)

Financial Sector OverlayGreen

GLBA-regulated financial institutions and GLBA-covered data are excluded from MODPA.

Claims (1):

  • MODPA excludes financial institutions and data subject to Title V of the Gramm-Leach-Bliley Act from its scope.

Health Sector OverlayGreen

HIPAA-covered data is excluded from MODPA scope, while MODPA separately regulates non-HIPAA consumer health data with geofencing bans.

Claims (1):

  • MODPA excludes HIPAA-covered data from its scope while separately regulating non-HIPAA 'consumer health data' with heightened protections including facility geofencing bans.

Telecoms And EprivacyRed

No Maryland-specific telecoms/eprivacy overlay distinct from MODPA was located.

Employment DataRed

No Maryland-specific employment-data privacy overlay was located.

Credit And ScoringGreen

FCRA-covered consumer-reporting-agency activity is excluded from MODPA's sensitive-data sale restrictions.

Claims (1):

  • MODPA excludes consumer-reporting-agency activity covered by the Fair Credit Reporting Act from its sensitive-data sale restrictions.

EducationGreen

FERPA-covered education records are excluded from MODPA.

Claims (1):

  • MODPA excludes data covered by the Family Educational Rights and Privacy Act from its scope.

InsuranceRed

No Maryland-specific insurance-sector privacy overlay was located.

Category narrative36 words

MODPA carves out several federally-regulated sectors: GLBA-covered financial institutions, HIPAA-covered health data, FCRA-covered consumer-reporting activity, and FERPA-covered education records are excluded from MODPA's scope, while MODPA itself separately regulates non-HIPAA 'consumer health data' with heightened protections.

Sources and claims (4)
  1. ConfirmedIAPPMODPA excludes financial institutions and data subject to Title V of the Gramm-Leach-Bliley Act from its scope.observed
  2. ConfirmedIAPPMODPA excludes HIPAA-covered data from its scope while separately regulating non-HIPAA 'consumer health data' with heightened protections including facility geofencing bans.observed
  3. ConfirmedIAPPMODPA excludes consumer-reporting-agency activity covered by the Fair Credit Reporting Act from its sensitive-data sale restrictions.observed
  4. ConfirmedIAPPMODPA excludes data covered by the Family Educational Rights and Privacy Act from its scope.observed

#

Targeted-advertising restrictions for minors and UOOM treatment are confirmed; cookie, dark-pattern, and clean-room specifics are unconfirmed.

Primary frameworkMaryland Online Data Privacy Act (MODPA), 2024
Traffic-light rationale — AmberTargeted-advertising restrictions for minors and UOOM treatment are confirmed; cookie, dark-pattern, and clean-room specifics are unconfirmed.

Sub-modules (6)

Cookies And TrackersRed

No MODPA-specific cookie/tracker consent provision distinct from general consent standards was located.

Dark PatternsAmber

MODPA's consent definition requiring 'unambiguous affirmative action' implicitly disfavours dark-pattern-obtained consent, consistent with peer state laws.

Claims (1):

  • MODPA defines consent as requiring an 'unambiguous affirmative action,' a standard that implicitly excludes consent obtained via manipulative interface design (dark patterns).

Opt Out SignalsAmber

MODPA treats universal opt-out mechanism recognition as optional rather than mandatory, a notable departure from most peer states.

Claims (1):

  • MODPA recognizes universal opt-out mechanisms as an optional alternative to a conspicuous 'do not sell' link rather than mandating recognition of such signals.

Clean Rooms And DcrRed

No clean-room or data-collaboration-room-specific provision was located under MODPA.

Cross Context AdvertisingGreen

MODPA bans targeted advertising to consumers a controller knew or should have known are under 18.

Claims (1):

  • MODPA bans processing personal data for targeted advertising where the controller knew or should have known the consumer is under 18, applying an expanded constructive-knowledge standard.

Direct MarketingRed

No MODPA provision specific to direct-marketing consent/suppression distinct from the general sale/targeted-advertising opt-out was located.

Category narrative35 words

MODPA's commercial-privacy provisions center on an under-18 targeted-advertising ban, an optional (not mandatory) universal opt-out mechanism, and an 'unambiguous affirmative action' consent standard that implicitly disfavours dark-pattern-obtained consent. No cookie-specific or clean-room-specific provisions were located.

Sources and claims (3)
  1. ProbableIAPPMODPA defines consent as requiring an 'unambiguous affirmative action,' a standard that implicitly excludes consent obtained via manipulative interface design (dark patterns).observed
  2. ConfirmedIAPPMODPA recognizes universal opt-out mechanisms as an optional alternative to a conspicuous 'do not sell' link rather than mandating recognition of such signals.observed
  3. ConfirmedIAPPMODPA bans processing personal data for targeted advertising where the controller knew or should have known the consumer is under 18, applying an expanded constructive-knowledge standard.observed

#

Biometric/genetic protections are confirmed via the sensitive-data regime; ADM transparency, profiling restrictions, and AI risk-assessment mandates are unconfirmed or still proposed.

Primary frameworkMaryland Online Data Privacy Act (MODPA), 2024
Traffic-light rationale — AmberBiometric/genetic protections are confirmed via the sensitive-data regime; ADM transparency, profiling restrictions, and AI risk-assessment mandates are unconfirmed or still proposed.

Sub-modules (6)

Profiling RestrictionsRed

No MODPA provision establishing a general profiling-restriction regime akin to GDPR Art. 22 was located.

Automated Decision Making TransparencyRed

No ADM-transparency/explanation-right provision was located under MODPA.

Ai Risk AssessmentsRed

Maryland is considering, but has not enacted, dedicated AI risk-assessment legislation separate from MODPA.

Claims (1):

  • Maryland lawmakers are considering AI-specific bills distinct from MODPA, including Senate Bill 827 on chatbot/generative-AI liability and House Bill 956 establishing an AI-implementation workgroup, indicating an emerging but not-yet-comprehensive state AI-governance overlay.

Biometric RegimeGreen

Biometric data is included in MODPA's sensitive-data category, subject to strict-necessity and sale-ban rules.

Claims (1):

  • MODPA includes biometric and genetic data within its 'sensitive data' definition, subjecting their collection, processing, and sharing to the 'strictly necessary' standard and an outright sale ban.

Genetic DataGreen

Genetic data is likewise included in MODPA's sensitive-data category under the same strict-necessity and sale-ban rules.

Claims (1):

  • MODPA includes biometric and genetic data within its 'sensitive data' definition, subjecting their collection, processing, and sharing to the 'strictly necessary' standard and an outright sale ban.

State Surveillance CarveoutsRed

No MODPA-specific national-security or state-surveillance carve-out provision was located in this run's sources.

Category narrative48 words

MODPA treats biometric and genetic data as sensitive data subject to strict-necessity and sale-ban rules, but contains no GDPR Art.22-style profiling-restriction or automated-decision-making-transparency regime. Maryland is separately considering (but has not yet enacted as of this run) AI-specific legislation such as chatbot/generative-AI liability and an AI oversight workgroup.

Sources and claims (2)
  1. UncertainDataGuidanceMaryland lawmakers are considering AI-specific bills distinct from MODPA, including Senate Bill 827 on chatbot/generative-AI liability and House Bill 956 establishing an AI-implementation workgroup, indicating an emerging but not-yet-comprehensive state AI-governance overlay.observed
  2. ConfirmedIAPPMODPA includes biometric and genetic data within its 'sensitive data' definition, subjecting their collection, processing, and sharing to the 'strictly necessary' standard and an outright sale ban.observed

#

Minor-targeted-advertising and Kids Code protections are confirmed; parental-consent, education-setting, and dependent-adult sub-modules are unconfirmed absences.

Primary frameworkMaryland Online Data Privacy Act (MODPA); Maryland Kids Code (Age-Appropriate Design Code)
Traffic-light rationale — AmberMinor-targeted-advertising and Kids Code protections are confirmed; parental-consent, education-setting, and dependent-adult sub-modules are unconfirmed absences.

Sub-modules (5)

Age VerificationAmber

MODPA uses a 'knew or should have known' constructive-knowledge standard rather than mandating affirmative age verification, though commentators note this could functionally require age-assurance practices.

Claims (1):

  • MODPA bans processing personal data for targeted advertising and prohibits the sale of personal data belonging to consumers the controller knew or should have known are under 18.

Minor Profiling BansGreen

MODPA bans targeted advertising and sale of data belonging to consumers known or reasonably known to be minors under 18.

Claims (1):

  • MODPA bans processing personal data for targeted advertising and prohibits the sale of personal data belonging to consumers the controller knew or should have known are under 18.

Education SettingsRed

No Maryland-specific education-settings privacy rule beyond the general FERPA carve-out was located.

Dependent AdultsRed

No Maryland-specific dependent-adult data-protection provision was located in this run's sources.

Category narrative63 words

Maryland protects minors' data through two instruments: MODPA's ban on targeted advertising/sale for consumers a controller knew or should have known are under 18, and the separate Maryland Kids Code requiring Privacy by Design/Default for products reasonably likely to be accessed by children, in force despite litigation risk. No Maryland-specific parental-consent mechanism distinct from federal COPPA, education-setting rule, or dependent-adult protection was located.

Sources and claims (2)
  1. ConfirmedIAPPMODPA bans processing personal data for targeted advertising and prohibits the sale of personal data belonging to consumers the controller knew or should have known are under 18.observed
  2. UncertainDataGuidanceMODPA itself does not impose a distinct parental-consent mechanism; federal COPPA continues to apply concurrently for children under 13, and this interaction remains outside MODPA's own text as reviewed.observed

#

Core enforcement powers and no-private-right-of-action posture are confirmed; regulator funding/capacity data and collective-redress interactions with the general Consumer Protection Act are unconfirmed.

Primary frameworkMaryland Online Data Privacy Act (MODPA); Maryland Consumer Protection Act (Title 13, Commercial Law)
Traffic-light rationale — AmberCore enforcement powers and no-private-right-of-action posture are confirmed; regulator funding/capacity data and collective-redress interactions with the general Consumer Protection Act are unconfirmed.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

AG enforcement runs through Consumer Protection Act unfair/deceptive-trade-practice provisions, with a discretionary 60-day cure right sunsetting in 2027.

Claims (2):

  • MODPA violations are treated as unfair, abusive, or deceptive trade practices subject to the enforcement and penalty provisions of Title 13 of the Maryland Commercial Law Article (Consumer Protection Act).
  • The AG may issue a notice of violation triggering a 60-day cure period before bringing an enforcement action, retains discretion over whether to grant the cure opportunity considering factors including violation volume and entity size, and this cure right sunsets in 2027.

Enforcement Activity IndexAmber

Pre-MODPA multistate breach enforcement (e.g., the Inmediata settlement) illustrates the AG's active data-security enforcement track record under PIPA/CPA/HIPAA.

Claims (1):

  • In 2023, the Maryland AG joined a 33-state settlement with health-data clearinghouse Inmediata over a data exposure affecting 1.5 million consumers (16,423 in Maryland), resolving alleged violations of the Maryland Consumer Protection Act, PIPA, and HIPAA.

Regulator Funding And CapacityRed

No specific budget or headcount data for the AG's privacy-enforcement capacity was located in this run's sources.

Collective Redress And Class ActionsRed

No MODPA-specific collective-redress mechanism was located; its interaction with general Maryland Consumer Protection Act private-action provisions remains unresolved in the sources reviewed.

Claims (1):

  • No MODPA-specific collective-redress or class-action mechanism was located; whether general Maryland Consumer Protection Act private-action provisions apply to MODPA-predicated claims was not resolved in the sources reviewed.

Private Right Of ActionGreen

MODPA does not create a private right of action; enforcement runs exclusively through the AG.

Claims (1):

  • MODPA does not create a private cause of action for violations; the Maryland Office of the Attorney General is responsible for enforcement.

Recent Developments 180DAmber

A 2026 amendment strengthened MODPA's sensitive-data and immigration-related protections effective July 1, 2026; further AI-liability and surveillance-pricing bills remain in progress.

Claims (2):

  • In 2026, Maryland enacted amendments strengthening MODPA's sensitive-data and immigration-enforcement-related protections, effective July 1, 2026.
  • Additional 2026 Maryland legislative proposals extend the state's data/AI agenda beyond MODPA, including Senate Bill 827 (chatbot/generative-AI liability), House Bill 895 (ban on surveillance-based dynamic pricing in grocery stores), and House Bill 956 (AI-implementation workgroup); their enactment status was not confirmed in this run.
Category narrative52 words

The Maryland AG has exclusive MODPA enforcement authority operating through the state Consumer Protection Act framework, including a discretionary 60-day cure period sunsetting in 2027, and no private right of action. A 2026 amendment strengthened sensitive-data and immigration-related protections effective July 1, 2026, and further AI/pricing-related bills are in the legislative pipeline.

Sources and claims (7)
  1. ConfirmedDataGuidanceMODPA violations are treated as unfair, abusive, or deceptive trade practices subject to the enforcement and penalty provisions of Title 13 of the Maryland Commercial Law Article (Consumer Protection Act).observed
  2. ProbableIAPPThe AG may issue a notice of violation triggering a 60-day cure period before bringing an enforcement action, retains discretion over whether to grant the cure opportunity considering factors including violation volume and entity size, and this cure right sunsets in 2027.observed
  3. ConfirmedMaryland Attorney GeneralIn 2023, the Maryland AG joined a 33-state settlement with health-data clearinghouse Inmediata over a data exposure affecting 1.5 million consumers (16,423 in Maryland), resolving alleged violations of the Maryland Consumer Protection Act, PIPA, and HIPAA.observed
  4. UncertainDataGuidanceNo MODPA-specific collective-redress or class-action mechanism was located; whether general Maryland Consumer Protection Act private-action provisions apply to MODPA-predicated claims was not resolved in the sources reviewed.observed
  5. ConfirmedDataGuidance (legacy)MODPA does not create a private cause of action for violations; the Maryland Office of the Attorney General is responsible for enforcement.observed
  6. ProbableDataGuidanceIn 2026, Maryland enacted amendments strengthening MODPA's sensitive-data and immigration-enforcement-related protections, effective July 1, 2026.observed
  7. UncertainDataGuidanceAdditional 2026 Maryland legislative proposals extend the state's data/AI agenda beyond MODPA, including Senate Bill 827 (chatbot/generative-AI liability), House Bill 895 (ban on surveillance-based dynamic pricing in grocery stores), and House Bill 956 (AI-implementation workgroup); their enactment status was not confirmed in this run.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Maryland
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 42 claim(s), 13 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, lawful_processing_and_special_data, sectoral_watch, children_and_vulnerable_groups, and enforcement_and_redress achieved multi-source T1/T3 coverage (Maryland AG primary docs plus DataGuidance/IAPP secondary analysis). data_subject_rights and controller_processor_duties are substantially covered but rely on T3 secondary commentary for exact response-window and DPO-related details, which could not be verified against primary statutory text in this run. cross_border_and_adequacy is correctly emitted as a legitimate absence (no state-level regime) rather than a silent omission. algorithmic_biometric_and_surveillance_governance and adtech_and_commercial_privacy are partially covered, with ADM-transparency, profiling-restriction, and cookie-specific provisions unconfirmed. No primary Maryland statutory text (mgaleg.maryland.gov) was directly fetchable in this run; all MODPA-specific findings rely on T1 Maryland AG procedural documents plus T3 legal-research/industry secondary sources.

Unresolved questions (5):

  • What is the exact statutory number of days within which a MODPA controller must respond to a consumer rights request, and is an extension permitted?
  • Does MODPA impose any explicit data-retention-limit or disposal-duty provision beyond purpose-based minimization?
  • Has Senate Bill 827 (chatbot/generative-AI liability), House Bill 895 (dynamic-pricing ban), or House Bill 956 (AI workgroup) been enacted as of the run date?
  • How does the general Maryland Consumer Protection Act's private-action provisions interact with MODPA's stated bar on a private right of action for MODPA-specific violations?
  • What is the current status and outcome of litigation challenging the Maryland Kids Code, and could it affect its 'fully in effect' status?

Escalate to primary-source review: yes