Law / Maryland

Maryland

age

Maryland's Age-Appropriate Design Code Act, the Kids Code, has been in effect since October 1, 2024 and is being challenged in federal court by NetChoice, with a motion to dismiss denied in November 2025 and no injunction in place. Maryland has not enacted an adult content age verification law or an app store accountability law: bills on both topics stalled in committee in 2025 and 2026. No dedicated social media minor-access bill has advanced past introduction.

privacy

The Maryland Online Data Privacy Act (MODPA), Md. Code Ann., Com. Law sections 14-4701 to 14-4714 (Title 14, Subtitle 47), is Maryland's comprehensive consumer-privacy regime, effective October 1, 2025. MODPA was enacted as House Bill 567, Chapter 454 (2024 Regular Session), under numbering the enrolled bill itself calls Subtitle 46; the Department of Legislative Services has since recodified the same provisions at Subtitle 47 in the live code, and Subtitle 47 is the citation used here.

MODPA reaches a wider population of controllers than most peer acts, applying at 35,000 consumers processed rather than the more common 100,000-consumer floor, with no independent revenue threshold. It has no separate lawful-basis list, instead imposing affirmative duties directly and gating sensitive data on strict necessity or consent.

Maryland has no dedicated biometric statute; genetic and biometric data collected to uniquely identify a person is folded into MODPA's sensitive-data category outright, and MODPA's biometric-data definition claws back data generated from a photograph, video, or audio recording the moment that data is generated to identify a specific consumer, so an identifier a product derives from a public recording for identification purposes falls inside sensitive data here.

A separate chapter, the Maryland Personal Information Protection Act (MPIPA), Md. Code Ann., Com. Law sections 14-3501 to 14-3508 (Title 14, Subtitle 35), governs breach notification and lists biometric data used to authenticate identity as its own triggering data element.

MODPA enforcement is exclusive to the Attorney General's Division of Consumer Protection; MODPA expressly excludes the Maryland Consumer Protection Act's private-action-for-damages provision from its enforcement scheme, so MODPA carries no private right of action. MPIPA's own enforcement section carries no such exclusion, so unlike MODPA, a MPIPA breach-notification violation is privately actionable.

17 instruments named 6 researched in detail As of 2026-08-27

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Age-appropriate design code

HB 603 / SB 571, Maryland Age-Appropriate Design Code Act (Kids Code)

cite Md. Code, Com. Law §§ 14-4801 to 14-4813 (Subtitle 48), 2024 Md. Laws ch. 461 stage IN FORCE in force since 2024-10-01 source official Maryland Code statute text

Requires online products reasonably likely to be accessed by children under 18 to set high default privacy settings, complete data protection impact assessments, and avoid data practices harmful to children. A First Amendment and federal preemption challenge by NetChoice survived a motion to dismiss in November 2025 and is proceeding without an injunction.

Note and primary source

Breach notification

Maryland Personal Information Protection Act (MPIPA), breach notification

cite Md. Code Ann., Com. Law §§ 14-3501, 14-3504 (Title 14, Subtitle 35) stage IMMINENT commencement not set source official Maryland statute text, Commercial Law Article, Title 14 Subtitle 35, Maryland General Assembly statute lookup

The Maryland Personal Information Protection Act, a separate chapter untouched by MODPA's enactment or later recodification, requires a business that owns, licenses, or maintains computerized data including personal information to notify each affected Maryland individual once it determines a likelihood the breach caused or will cause misuse, as soon as reasonably practicable and no later than 45 days after concluding its investigation, with an extension to 30 days after any law-enforcement delay is cleared.

'Personal information' includes biometric data generated by automatic measurement of an individual's biological characteristics, such as a fingerprint, voiceprint, genetic print, or retina or iris image, used to uniquely authenticate identity when accessing a system or account, alongside the more familiar Social Security, driver's license, or financial account number data elements.

MPIPA's own enforcement section, § 14-3508, makes a violation an unfair or deceptive trade practice subject to Title 13's enforcement and penalty provisions, and unlike MODPA's § 14-4713, it does not exclude § 13-408, the Maryland Consumer Protection Act's private-action-for-damages provision, so a MPIPA violation is privately actionable through that route.

What it asks of an app

Comprehensive regime

Maryland Online Data Privacy Act (MODPA), general applicability and controller/processor duties

cite Md. Code Ann., Com. Law §§ 14-4701, 14-4702 (Title 14, Subtitle 47) stage RECENT in force 11 months effective 2025-10-01 source official Maryland statute text, Commercial Law Article, Title 14 Subtitle 47, Maryland General Assembly statute lookup

MODPA governs private-sector processing of Maryland residents' personal data.

It applies to a person that conducts business in Maryland or targets products or services to Maryland residents and, in the preceding calendar year, either controlled or processed at least 35,000 consumers' personal data (excluding data processed solely to complete a payment transaction) or controlled or processed at least 10,000 consumers' personal data while deriving more than 20% of gross revenue from selling personal data.

MODPA carries no independent revenue threshold, and its 35,000-consumer floor is materially lower than many peer states' 100,000-consumer floor. A controller determines the purpose and means of processing; a processor processes on a controller's behalf.

What it asks of an app

Data subject rights

Maryland Online Data Privacy Act (MODPA), consumer rights and appeal

cite Md. Code Ann., Com. Law § 14-4705 stage RECENT in force 11 months effective 2025-10-01 source official Maryland statute text, Commercial Law Article, Title 14 Subtitle 47, Maryland General Assembly statute lookup

MODPA gives a Maryland consumer the right, exercisable against a controller, to confirm processing, access their personal data, correct inaccuracies, delete data, obtain a portable copy for automated-processing data, obtain a list of categories of third parties their data was disclosed to, and opt out of targeted advertising, sale, or profiling in furtherance of solely automated decisions with legal or similarly significant effects.

A controller must respond within 45 days of receipt, with one 45-day extension available if the controller informs the consumer of the extension and its reason within the initial period, and must establish a conspicuous process to appeal a refusal.

What it asks of an app

Enforcement supervision

Maryland Online Data Privacy Act (MODPA), Attorney General enforcement and cure period

cite Md. Code Ann., Com. Law §§ 14-4713, 14-4714 stage RECENT in force 11 months effective 2025-10-01 source official Maryland statute text, Commercial Law Article, Title 14 Subtitle 47, Maryland General Assembly statute lookup

A MODPA violation is an unfair, abusive, or deceptive trade practice enforced under the Maryland Consumer Protection Act's (Title 13) machinery, except that MODPA expressly excludes section 13-408, the Consumer Protection Act's private-action-for-damages provision, from its enforcement scheme, so a MODPA violation is not independently privately actionable through that route.

Section 14-4713(b) preserves any other remedy provided by law as a savings clause, not a grant of a private cause of action. Before initiating an enforcement action for a violation occurring on or before April 1, 2027, the Division of Consumer Protection may, in its discretion, issue a notice of violation where it determines a cure is possible, giving the controller or processor at least 60 days to cure; there is no unconditional right to cure, and this mechanism itself sunsets.

What it asks of an app

Sensitive categories

Maryland Online Data Privacy Act (MODPA), sensitive data and biometric consent

cite Md. Code Ann., Com. Law §§ 14-4701(d), (gg), 14-4707(a) stage RECENT in force 11 months effective 2025-10-01 source official Maryland statute text, Commercial Law Article, Title 14 Subtitle 47, Maryland General Assembly statute lookup

MODPA classifies genetic or biometric data, alongside racial or ethnic origin, religious belief, health data, sexuality, transgender or nonbinary status, national origin, citizenship or immigration status, a known child's data, and precise geolocation, as sensitive data.

A controller may not collect, process, or share sensitive data unless strictly necessary to provide a product or service the consumer requested, may never sell sensitive data, and may not process or sell a consumer's personal data for targeted advertising if it knew or should have known the consumer is under 18.

'Biometric data' means data from automatic measurement of a consumer's biological characteristics used to uniquely authenticate identity, including a fingerprint, voiceprint, or eye retina or iris image, and excludes a bare photograph or an audio or video recording, but claws that exclusion back the moment data generated from one is generated to identify a specific consumer.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.