Law note · Maryland
Maryland Online Data Privacy Act (MODPA), publicly available information exemption and biometric carve-back
What it asks of an app
- Never treat biometric data you collect about a Maryland consumer without that consumer's knowledge as publicly available, even if the source photo or recording appeared on a public page; MODPA's own carve-back excludes it from the exemption regardless.
- Limit any personal data you collect on a Maryland consumer to what is reasonably necessary and proportionate to the specific product or service they requested; MODPA has no broader compatible-purpose alternative to fall back on.
- If you meet MODPA's 35,000-consumer or 10,000-consumer-plus-20%-revenue thresholds, expect enforcement only from the Maryland Attorney General; the Act carries no private right of action.
When LexLint raises it
crawls_webtrains_modelsprocesses_biometrics
What we found
MODPA excludes publicly available information from personal data, defined to mean information lawfully made available through government records or that a controller reasonably believes the consumer lawfully made available to the public through widely distributed media.
Unusually among the comprehensive state privacy acts researched in this wave, the definition carries an express carve-back: publicly available information does not include biometric data collected by a business about a consumer without the consumer's knowledge, so a scraper harvesting public biometric identifiers, such as faces from public photos for facial-recognition purposes, cannot rely on the publicly-available exemption in Maryland even though the same photos would fall outside personal data entirely if they were merely names or contact details.
MODPA also carries the strictest data-minimization rule among the comprehensive state privacy acts, requiring a controller to limit the collection of personal data to what is reasonably necessary and proportionate to provide or maintain a specific product or service the consumer requested, with no separate or compatible disclosed purpose alternative of the kind most peer statutes carry.
The Act applies to a controller conducting business in Maryland, or targeting Maryland residents, that in the preceding calendar year controlled or processed personal data of at least 35,000 consumers (excluding payment-only data), or of at least 10,000 consumers while deriving more than 20% of gross revenue from personal-data sales. As enacted, the chapter was codified at Com. Law section 14-4601 et seq.
The 2025 Replacement Volume recodification to section 14-4701 et seq. is confirmed directly against the state's own statute lookup (mgaleg.maryland.gov): section 14-4601 now returns an unrelated Forensic Nurse Examiner Training Grant Program provision, while section 14-4701 carries this Act's own definitions and cross-references its consumer-rights section at section 14-4705, so section 14-4701 et seq. is the current citation.
The Act's own enactment clause states it shall take effect October 1, 2025, correcting an earlier drafting date. Enforcement runs through the penalty provisions of Title 13 of the Commercial Law Article (the Maryland Consumer Protection Act) except for section 13-408, that article's own private-right-of-action section, so there is no private right of action and enforcement is by the Maryland Attorney General.