Law note · Maryland
Maryland Online Data Privacy Act (MODPA), general applicability and controller/processor duties
MODPA governs private-sector processing of Maryland residents' personal data.
It applies to a person that conducts business in Maryland or targets products or services to Maryland residents and, in the preceding calendar year, either controlled or processed at least 35,000 consumers' personal data (excluding data processed solely to complete a payment transaction) or controlled or processed at least 10,000 consumers' personal data while deriving more than 20% of gross revenue from selling personal data.
MODPA carries no independent revenue threshold, and its 35,000-consumer floor is materially lower than many peer states' 100,000-consumer floor. A controller determines the purpose and means of processing; a processor processes on a controller's behalf.
What it asks of an app
- Determine whether you conduct business in Maryland or target products or services to Maryland residents, and controlled or processed at least 35,000 consumers' personal data (excluding data processed solely to complete a payment transaction) or at least 10,000 consumers' personal data while deriving more than 20% of gross revenue from selling personal data, before treating MODPA as out of scope.
- Treat Maryland's 35,000-consumer applicability floor as materially lower than many peer states' 100,000-consumer floor when deciding whether MODPA reaches your Maryland-facing processing.
- Allocate controller duties (determining the purpose and means of processing) and processor duties (processing on a controller's behalf) correctly before assigning any of MODPA's other duties.
When LexLint raises it
Declared activities: automated_outreach, crawls_web, deploys_chatbot, processes_biometrics, processes_voice, trains_models
Primary source: official Maryland statute text, Commercial Law Article, Title 14 Subtitle 47, Maryland General Assembly statute lookup