iQ Cookie  State Law Series

State 11 of 25 · Maryland

Cookie & Privacy Law in Maryland

Published August 2026
Law in effect
Enforcement began April 1, 2026

Educational purposes only — not legal advice. This guide is intended to help you understand Maryland’s data privacy law as it relates to cookie consent and website compliance. Laws change, and your specific situation may vary. Always consult a qualified legal professional before making compliance decisions. iQ Cookie is a technology tool, not a law firm.

LAW
MODPA
SB 541 / HB 567
SIGNED
May 9, 2024
Effective Oct 1, 2025
ENFORCEMENT
Apr 1, 2026
Grace period ended
STATE RANK
#17
To enact a law

The short version

Maryland is widely considered the strictest comprehensive privacy law in the country — a real departure from the Virginia model most states have copied. It took effect October 1, 2025, with a grace period before enforcement kicked in on April 1, 2026. Where most states let you sell sensitive data with opt-in consent, Maryland simply bans selling it. Where most states say collect what is "reasonably necessary," Maryland means it literally, with one of the tightest data minimization standards on the books.

Maryland does not have a separate cookie law. Cookie compliance flows from the MODPA itself — and because Maryland’s baseline is stricter, so are the cookie-specific obligations.

Maryland General Assembly — Official Text
Maryland Online Data Privacy Act, SB 541 / HB 567

Who does it apply to?

The MODPA covers businesses that conduct business in Maryland or target Maryland residents, and meet at least one of these thresholds:

THRESHOLD 1

Controls or processes personal data of 35,000 or more Maryland consumers — no revenue floor on this path at all.

THRESHOLD 2

Controls or processes data of 10,000 or more consumers AND derives more than 20% of gross revenue from selling personal data.

35,000 consumers is a genuinely low bar. That works out to about 0.56% of Maryland’s population — roughly a third of the share Colorado requires, and a sixth of Delaware’s. Mid-sized regional sites can trip this without realizing it.

Nonprofits, government entities, and higher-education institutions are exempt.

Consumer rights

Maryland residents whose data is covered by the MODPA have these rights:

Access
Confirm whether their data is being processed and receive a copy
Correct
Fix inaccurate personal data
Delete
Request removal of personal data
Portability
Receive data in a usable, portable format
Opt out
Sale, targeted advertising, and profiling
Limit sensitive data use
On top of the outright sale ban below

Businesses must respond within 45 days, extendable once by another 45. There is no private right of action — only the Attorney General’s Consumer Protection Division can enforce.

What makes Maryland different

Selling sensitive data is banned outright. Most states let you sell sensitive data with opt-in consent. Maryland does not offer that option — race, religion, health data, sexual orientation, biometric data, and more simply cannot be sold, consent or no consent.

The strictest data minimization standard in the country. Controllers may only collect what is "reasonably necessary and proportionate" to the specific product or service requested — not just disclosed, actually necessary. Broad "collect everything, disclose it in the policy" approaches do not satisfy this.

No sale or targeted ads to anyone under 18. Maryland sets its minors’ bar at 18, not 13 or 16 like most peer states — and it applies whenever the controller knew or reasonably should have known the consumer’s age.

GPC is mandatory. Controllers must recognize and honor Global Privacy Control and similar universal opt-out signals from the law’s effective date — no phase-in delay like some other states used.

Penalties run well above the typical state cap. $10,000 for an initial violation, $25,000 for a repeat one — both meaningfully higher than the $7,500 ceiling most Virginia-model states use.

Sensitive data & children

Sensitive data cannot be sold under any circumstances, and processing it for other purposes requires opt-in consent. Sensitive data includes:

Racial / ethnic origin
Religious beliefs
Health diagnosis & consumer health data
Sexual orientation
Citizenship / immigration status
Biometric data
Genetic data
Precise geolocation (1,750 ft)
Children’s data

Anyone under 18 gets blanket protection from data sale and targeted advertising — this is broader than the usual under-13 or under-16 carve-outs and applies whenever age is known or reasonably knowable.

What this means for your cookies

Cookie typeRequirementWhat to do
Sensitive data cookies (health, biometric, geolocation)Sale bannedNever sell data from these cookies — opt-in consent does not make that legal in Maryland.
Targeted advertising cookiesOpt-out requiredProvide a clear opt-out mechanism, and confirm data collection is minimized to what is needed.
GPC / opt-out signalsRequiredDetect and honor the signal automatically, site-wide.
Any cookies — users under 18No sale or targeted adsBlock sale and targeted-ad cookies for known or reasonably-known minors under 18.
Analytics & "nice to have" trackingRe-check necessityMaryland’s minimization standard means "useful" is not enough — confirm each cookie is actually necessary for the service.

Enforcement

$10,000
Initial violation
$25,000
Repeat violation
60 days
Cure period until Apr 1, 2027

The Maryland Attorney General’s Consumer Protection Division has exclusive enforcement authority, with no private right of action. A 60-day cure period is available at the AG’s discretion until April 1, 2027 — after that, whether to offer one becomes entirely optional. With penalties well above the typical state cap and enforcement now active as of April 2026, Maryland is one to take seriously.

Your action checklist

Enforcement is already active — here is what to have in place now:

1

Check your threshold carefully. 35,000 Maryland consumers with no revenue floor is a low bar — run the numbers even if you assumed you were too small.

2

Stop selling sensitive data, period. No consent flow makes this legal in Maryland. Audit any cookies or vendor relationships that involve selling health, biometric, or similar data.

3

Re-audit data minimization. For every cookie and data point you collect, be ready to justify why it is reasonably necessary and proportionate — not just disclosed.

4

Confirm GPC recognition is live and working. This is mandatory from day one in Maryland, with no delayed phase-in.

5

Block sale and targeted ads for anyone under 18. Maryland’s bar is higher than most states — treat unknown-age users conservatively if minors could reach your site.

6

Update your privacy policy. Cover data categories, purposes, consumer rights, and be explicit that sensitive data is never sold.

7

Review vendor contracts. Any processor handling Maryland resident data must be covered by a written agreement specifying processing instructions and confidentiality obligations.

Not sure where your site stands with Maryland?

iQ Cookie scans your site against Maryland’s stricter standards and deploys a lightweight US-built consent banner.

iQ Cookie State Law Series  ·  Guide 11 of 25  ·  Next: Minnesota →