Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Age-appropriate design code
Requires online products reasonably likely to be accessed by children under 18 to set high default privacy settings, complete data protection impact assessments, and avoid data practices harmful to children. A First Amendment and federal preemption challenge by NetChoice survived a motion to dismiss in November 2025 and is proceeding without an injunction.
Note and primary source →
Breach notification
The Maryland Personal Information Protection Act, a separate chapter untouched by MODPA's enactment or later recodification, requires a business that owns, licenses, or maintains computerized data including personal information to notify each affected Maryland individual once it determines a likelihood the breach caused or will cause misuse, as soon as reasonably practicable and no later than 45 days after concluding its investigation, with an extension to 30 days after any law-enforcement delay is cleared.
'Personal information' includes biometric data generated by automatic measurement of an individual's biological characteristics, such as a fingerprint, voiceprint, genetic print, or retina or iris image, used to uniquely authenticate identity when accessing a system or account, alongside the more familiar Social Security, driver's license, or financial account number data elements.
MPIPA's own enforcement section, § 14-3508, makes a violation an unfair or deceptive trade practice subject to Title 13's enforcement and penalty provisions, and unlike MODPA's § 14-4713, it does not exclude § 13-408, the Maryland Consumer Protection Act's private-action-for-damages provision, so a MPIPA violation is privately actionable through that route.
What it asks of an app →
Comprehensive regime
MODPA governs private-sector processing of Maryland residents' personal data.
It applies to a person that conducts business in Maryland or targets products or services to Maryland residents and, in the preceding calendar year, either controlled or processed at least 35,000 consumers' personal data (excluding data processed solely to complete a payment transaction) or controlled or processed at least 10,000 consumers' personal data while deriving more than 20% of gross revenue from selling personal data.
MODPA carries no independent revenue threshold, and its 35,000-consumer floor is materially lower than many peer states' 100,000-consumer floor. A controller determines the purpose and means of processing; a processor processes on a controller's behalf.
What it asks of an app →
Data subject rights
cite Md. Code Ann., Com. Law § 14-4705
stage RECENT in force 11 months
effective 2025-10-01
source official Maryland statute text, Commercial Law Article, Title 14 Subtitle 47, Maryland General Assembly statute lookup
MODPA gives a Maryland consumer the right, exercisable against a controller, to confirm processing, access their personal data, correct inaccuracies, delete data, obtain a portable copy for automated-processing data, obtain a list of categories of third parties their data was disclosed to, and opt out of targeted advertising, sale, or profiling in furtherance of solely automated decisions with legal or similarly significant effects.
A controller must respond within 45 days of receipt, with one 45-day extension available if the controller informs the consumer of the extension and its reason within the initial period, and must establish a conspicuous process to appeal a refusal.
What it asks of an app →
Enforcement supervision
cite Md. Code Ann., Com. Law §§ 14-4713, 14-4714
stage RECENT in force 11 months
effective 2025-10-01
source official Maryland statute text, Commercial Law Article, Title 14 Subtitle 47, Maryland General Assembly statute lookup
A MODPA violation is an unfair, abusive, or deceptive trade practice enforced under the Maryland Consumer Protection Act's (Title 13) machinery, except that MODPA expressly excludes section 13-408, the Consumer Protection Act's private-action-for-damages provision, from its enforcement scheme, so a MODPA violation is not independently privately actionable through that route.
Section 14-4713(b) preserves any other remedy provided by law as a savings clause, not a grant of a private cause of action. Before initiating an enforcement action for a violation occurring on or before April 1, 2027, the Division of Consumer Protection may, in its discretion, issue a notice of violation where it determines a cure is possible, giving the controller or processor at least 60 days to cure; there is no unconditional right to cure, and this mechanism itself sunsets.
What it asks of an app →
Sensitive categories
MODPA classifies genetic or biometric data, alongside racial or ethnic origin, religious belief, health data, sexuality, transgender or nonbinary status, national origin, citizenship or immigration status, a known child's data, and precise geolocation, as sensitive data.
A controller may not collect, process, or share sensitive data unless strictly necessary to provide a product or service the consumer requested, may never sell sensitive data, and may not process or sell a consumer's personal data for targeted advertising if it knew or should have known the consumer is under 18.
'Biometric data' means data from automatic measurement of a consumer's biological characteristics used to uniquely authenticate identity, including a fingerprint, voiceprint, or eye retina or iris image, and excludes a bare photograph or an audio or video recording, but claws that exclusion back the moment data generated from one is generated to identify a specific consumer.
What it asks of an app →