What Maryland’s privacy law says, in plain words
The Maryland Online Data Privacy Act, usually shortened to MODPA, began as Senate Bill 541 and House Bill 567 of the 2024 session and became Chapters 454 and 455 of 2024 when Governor Moore signed it that May. It lives in the Commercial Law Article as Title 14, Subtitle 47, sections 14–4701 through 14–4714. It took effect on 1 October 2025, and an uncodified section of the Act keeps it from reaching any processing of personal data that happened before 1 April 2026. It has been fully live for a little over five months, and whether it applies to your store in 2027 will be decided by what you do this year.
Who it covers takes one sentence:
“This subtitle applies to a person that conducts business in the State or provides products or services that are targeted to residents of the State, and that during the preceding calendar year did any of the following: (1) Controlled or processed the personal data of at least 35,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; or (2) Controlled or processed the personal data of at least 10,000 consumers and derived more than 20% of its gross revenue from the sale of personal data.” — Md. Commercial Law §14–4702
Everything else in the subtitle hangs off that sentence. The terms it uses are defined in §14–4701: a consumer is an individual who is a resident of Maryland, a controller is whoever decides the purpose and means of processing personal data, and personal data is any information that is linked or can be reasonably linked to an identified or identifiable consumer. There is no revenue floor. A two-person shop with a big email list can be inside the law, while a large wholesaler whose customers are all businesses can sit outside it.
Enforcement belongs to the Attorney General’s Consumer Protection Division. A violation is an unfair, abusive or deceptive trade practice under the Maryland Consumer Protection Act and carries that Act’s enforcement and penalty provisions, with one exception: §13–408, the section that lets a consumer sue for damages, does not apply. So there are no private lawsuits under MODPA. There is a state agency with the power to seek up to $10,000 per violation and $25,000 for each repetition.
The count is people, not customers
Read §14–4702 slowly and notice what it does not say. It does not say customers, orders or accounts. It says consumers whose personal data you controlled or processed, and the statute defines process about as widely as the language allows: collecting, using, storing, disclosing, analyzing, deleting or modifying. An email address that has sat on your newsletter list since 2022, belonging to someone who has never opened a single message, is data you are storing. A customer from three Christmases ago whose order history is still in your admin counts in every year you keep it. Even deleting a record is, by the letter of the definition, processing it; a 2026 bill that would have taken deletion out of the definition, Senate Bill 569, died in committee after its hearing.
Two groups fall out of the count, and both are useful. An individual acting in a commercial or employment context is not a consumer at all, so the café owner who buys your coffee wholesale, the office manager who reorders supplies for a firm, your own staff and your job applicants are all outside it. For a Baltimore business that sells to other businesses as well as to the public, those contacts can be a large share of the database, and none of them count. And a consumer is a Maryland resident. Customers in Pennsylvania, Virginia or Delaware are not Maryland consumers, although their own states may have a view about them, which I come back to below.
The last detail is the calendar. The count covers the preceding calendar year, which means the number that decides whether MODPA applies to your store next year is being made right now, between January and December of 2026.
What the payment exclusion leaves out
The only carve-out in the count is for personal data “controlled or processed solely for the purpose of completing a payment transaction.” It is written for the business that takes a card, completes the sale and keeps nothing. The word doing the work is solely. A card number passing through your processor to settle an order is the easy case. The same customer’s email address copied into your marketing list, the order kept for returns and reorders, the saved address and the account login are not processed solely to complete a payment, and each of them puts that person back into the count.
That produces a result worth saying plainly: one checkout, two counts. Two Baltimore shops can run the same number of Maryland checkouts through the same payment processor, and one can sit outside the law while the other sits inside it, because one keeps the order and emails the customer afterward and the other does not. The statute does not say whether a receipt email, or an order record kept only because tax law requires it, is part of completing the payment. I would not build a compliance plan on the generous reading. Treat the payment itself as the only thing excluded, and count everything you keep around it.
The visitors nobody counts
The hardest part of the count is the part most small stores never think about: the people who visit and do not buy. MODPA calls a consumer identifiable if the consumer “can readily be identified, either directly or indirectly.” A browser cookie on its own is not a name. But the advertising pixels most stores install exist precisely to connect a browser to a person across sites, and the statute’s own definition of targeted advertising speaks of ads shown “on a device identified by a unique identifier.”
The statute does not say whether an analytics identifier for a visitor who never logs in is personal data, and I have not found guidance from the Attorney General’s office that settles it. Practitioners disagree. The cautious reading, and the one I would plan around, is that any visitor your analytics or advertising tools can recognize again is a person whose data you process. On that reading the count is not orders and not customers. It is people, and a website meets far more of them than a till ever does.
| Where the data sits | Counts toward 35,000? | Why |
|---|---|---|
| Card details passing through your processor to complete a sale | No, if used solely for that | The payment exclusion in §14–4702(1) |
| Order history kept for fulfillment, returns and reorders | Yes | Stored and used beyond completing the payment |
| Customer accounts and saved addresses | Yes | Stored personal data |
| Email and SMS subscribers, including people who never bought | Yes | Collected and stored personal data |
| Loyalty and rewards members | Yes | Collected and used, under the loyalty rule in §14–4707(c)(2) |
| Reviews, chat transcripts and helpdesk tickets | Yes | Linked to an identifiable person |
| Visitors your analytics or ad pixels can recognize again | Unsettled; yes on the cautious reading | Information that “can be reasonably linked” to an identifiable consumer |
| Wholesale buyers and other business contacts | No | Not consumers: a commercial context |
| Staff and job applicants | No | Not consumers: an employment context, and exempt under §14–4703(b)(11) |
| Customers who live outside Maryland | No | Not Maryland residents, though their own state’s law may count them |
Four of those ten rows fall outside the count and one is unsettled. The other five are where most stores keep most of their customers, which is why the arithmetic below uses people rather than orders.
The arithmetic: why the local shop crosses first
Once the count is people, a feature of the threshold appears that I have not seen much written about, and it matters more in Baltimore than almost anywhere. The law counts Maryland residents, so how quickly a store reaches 35,000 of them depends less on how big the store is than on where its audience lives.
The Census Bureau puts Maryland’s population at 6,265,347 on 1 July 2025, which is 1.833% of the country’s 341,784,857. The threshold of 35,000 is 0.559% of Marylanders, about one resident in every 179. A national online store whose visitors are spread like the population meets one Marylander for every 54.6 people it meets. A shop in Hampden or Fells Point whose website is found mostly by people who live nearby meets a Marylander almost every time. Baltimore City alone has 569,997 residents, so a shop whose customers all live in the city reaches the line when about one city resident in 16 has left some data with it.
Here is what that does to the size a store has to reach before the law applies, on the cautious reading where every person whose data you handle counts once a year.
| Share of your audience in Maryland | People a year to reach 35,000 Marylanders | New people a month | Compared with the 80% shop |
|---|---|---|---|
| 80% (a neighborhood shop) | 43,750 | 3,646 | 1.00× |
| 60% | 58,333 | 4,861 | 1.33× |
| 40% (a regional brand) | 87,500 | 7,292 | 2.00× |
| 15% (a Mid-Atlantic brand) | 233,333 | 19,444 | 5.33× |
| 1.833% (a national store, visitors spread like the population) | 1,909,307 | 159,109 | 43.64× |
The same threshold asks 43,750 people a year of a shop whose audience is 80% Maryland and 1.91 million of a national store: 43.6 times as many. In monthly terms, the Baltimore shop crosses the line if about 3,646 new people a month find it and leave something behind, whether an order, an email address or a cookie its tools can recognize. The national store needs about 159,109 new people a month. Maryland has written a threshold that small local businesses meet before small national ones do, and for most Baltimore stores that is the most useful single thing to understand about it.
Two cautions about that table. People are not visits: someone who comes back twelve times a year is one consumer, not twelve, so traffic reports overstate the count. Analytics tools also overstate it in a second way, because one person on a phone and a laptop usually shows up as two users. Neither caution changes the shape of the result. A Baltimore shop with a steady local audience and a busy email list should assume it is closer to the line than its order count suggests.
Who does that describe? The Census Bureau’s County Business Patterns for 2023 count 653 Maryland establishments whose main business is selling online or by mail, the category the Census calls electronic shopping and mail-order houses (NAICS 454110, the 2017 code the 2023 files still use). Between them they employ 19,447 people, and 459 of the 653, or 70.3%, have fewer than five employees. Baltimore City has 46, and 33 of those have fewer than five. Those figures undercount the stores this law reaches, because a bakery or a bike shop that also sells online is counted as a bakery or a bike shop, and County Business Patterns counts only businesses with paid employees. What they do show is that the typical Maryland business selling online is tiny. MODPA has no small-business exemption to catch it; the only question is the count.
The neighbors draw the line in different places
A Baltimore store’s nearest out-of-state customers live in Delaware, Pennsylvania, Virginia, the District and New Jersey, and each draws its line differently. I have set each threshold against that jurisdiction’s own population, using the same Census estimates.
| Jurisdiction | Main threshold (consumers a year) | Alternative threshold | Population, 2025 | Threshold as a share of residents | In force |
|---|---|---|---|---|---|
| Maryland | 35,000 | 10,000 and more than 20% of revenue from selling data | 6,265,347 | 0.559% (1 in 179) | 1 Oct 2025 |
| Delaware, through 31 Dec 2026 | 35,000 | 10,000 and more than 20% of revenue from selling data | 1,059,952 | 3.302% (1 in 30) | 1 Jan 2025 |
| Delaware, from 1 Jan 2027 | 10,000 | 5,000 and more than 20% of revenue from selling data | 1,059,952 | 0.943% (1 in 106) | 1 Jan 2027 |
| New Jersey | 100,000 | 25,000 and any revenue or discount from selling data | 9,548,215 | 1.047% (1 in 95) | 15 Jan 2025 |
| Virginia | 100,000 | 25,000 and more than 50% of revenue from selling data | 8,880,107 | 1.126% (1 in 89) | 1 Jan 2023 |
| Pennsylvania | no comprehensive law in force | — | 13,059,432 | — | — |
| District of Columbia | no comprehensive law | — | 693,645 | — | — |
Even after Delaware’s cut takes effect in January, Maryland asks for the smallest slice of its own residents of any state on that list: one in 179, against one in 106 in Delaware, one in 95 in New Jersey and one in 89 in Virginia. Connecticut, which lowered its own threshold to 35,000 on 1 July 2026, sits at about one in 105. Delaware’s amendment, House Bill 380, was signed on 2 September 2026 and takes effect on 1 January 2027; besides the lower thresholds, it adds inferred characteristics to sensitive data, the same move Maryland made in July (a law-firm summary of HB 380). New Jersey banned the sale of sensitive data this summer, and Virginia banned the sale of precise geolocation data from 1 July (Morgan Lewis has the round-up). Pennsylvania, where plenty of Baltimore orders ship, has no comprehensive consumer privacy law in force; its House passed one, HB 78, in October 2025. Neither does the District of Columbia.
Being fair to the law
It would be easy to write about MODPA as a trap, and it would not be honest. Most of what it asks of a small store is what a careful developer would do anyway: collect what the order needs, keep it safe, let people see and delete what you hold, and do not quietly sell it.
It is also narrower than its reputation. Business contacts and employees are out of the count. Health information that doctors and pharmacies hold as protected health information under HIPAA is exempt, and so is any financial institution covered by the Gramm-Leach-Bliley Act. Nobody can sue a store for damages under it. For violations through 1 April 2027, the Consumer Protection Division may send a notice and give a business at least 60 days to fix the problem before it brings an action, and the factors it weighs in offering that chance include the size and complexity of the business and whether the violation was likely caused by human or technical error (§14–4714). A small shop that finds a problem and fixes it is not the case the law was written for.
The Attorney General’s office has not, so far, gone looking for corner shops. When NPR asked about the new provisions in late June, a spokesperson for the office said: “Entities subject to the law should ensure they are in compliance.” The loudest use of the law since then has been aimed somewhere else entirely. On 19 August 2026 a coalition led by We Are CASA, with a complaint written by Georgetown Law’s technology law clinic and joined by groups including the Center for Democracy & Technology and the Electronic Privacy Information Center, asked the Attorney General to investigate data brokers and license-plate-reader companies it accuses of selling Marylanders’ location data and of selling to immigration enforcement (NPR). Two of the companies named denied the allegations, and the Attorney General’s office declined to comment. Nobody is filing 29-page complaints about bakeries.
Capacity is thin, too. A bill this year to create a dedicated Division of Data Protection inside the Attorney General’s office, with a workgroup to study how the law is working, passed the Senate in March and went no further in the House (Senate Bill 564).
The honest objection is about words rather than intent. The law’s central tests, reasonably necessary and proportionate for ordinary data and strictly necessary for sensitive data, are exactly the kind of phrase a developer cannot turn into a rule without guessing, and the only thing that settles what they mean is enforcement. House Bill 1365 in 2025 would have replaced the collection standard with the purpose-based wording most other states use, and it died after a hearing. The words are staying, and for now nobody outside the Attorney General’s office knows exactly where they draw the line. That is the real case for building conservatively: not because a fine is likely, but because being the test case is expensive.
The part no banner handles: sensitive data can live in the cart
Every online store collects personal data. What MODPA adds, and what most of the compliance tools sold to small stores do not touch, is a second category with much stricter rules, and the surprise for a store is where that category turns up.
Sensitive data, under §14–4701(gg), is personal data revealing racial or ethnic origin, religious beliefs, consumer health data, sex life, sexual orientation, status as transgender or nonbinary, national origin, or citizenship or immigration status; genetic or biometric data; personal data of a consumer the controller knows or has reason to know is a child; and precise geolocation data. Consumer health data is personal data a controller uses to identify a consumer’s physical or mental health status, and it expressly includes data related to reproductive or sexual health care, which the statute defines as health care services and products concerning a consumer’s reproductive system or sexual well-being, including the purchase of a medication and a product related to a bodily function, vital sign or symptom.
Then read what a store may do with it:
“A controller may not: (1) Except where the collection or processing is strictly necessary to provide or maintain a specific product or service requested by the consumer to whom the personal data pertains, collect, process, or share sensitive data concerning a consumer; (2) Sell sensitive data” — Md. Commercial Law §14–4707(a)
Most state privacy laws let a business process sensitive data once the consumer consents. Maryland’s does not. There is no consent exception in that sentence: a store may use sensitive data for what the customer asked for and nothing else, and it may never sell it, whatever the customer agrees to. Then, on 1 July 2026, Chapter 874 of 2026 added one paragraph that turns this from a rule about records into a rule about software:
“‘Sensitive data’ includes data inferred by a controller based on personal data that, alone or in combination with other data, is used to indicate any data described under paragraph (1)(i) through (iv) of this subsection.” — Md. Commercial Law §14–4701(gg)(2), as amended by Chapter 874 of 2026
Put the two together and the sensitivity of an order stops being a property of the customer table. It becomes a property of the product catalog, and of what the store’s software does with the catalog. A coffee roaster’s order history is ordinary personal data. A store that sells home pregnancy tests keeps a table that looks identical, with the same columns, and it is holding consumer health data. A recommendation feature that notices a run of prenatal vitamins followed by a crib, and tags the customer as expecting, has, since July, created sensitive data by inference, and nothing the customer asked for makes that tag strictly necessary.
| The data | What MODPA calls it | What the store may do with it |
|---|---|---|
| An order for a bag of coffee beans | Ordinary personal data | Use it for the order and, with the usual notice and opt-outs, for marketing |
| An order for a home pregnancy test | Consumer health data, because it relates to reproductive or sexual health care: sensitive | Fulfill the order. No ad events naming it, no audiences, no sale; staff see it only under a duty of confidentiality (§14–4704) |
| A customer tagged “likely expecting” from vitamin and crib purchases | Sensitive data by inference, since 1 July 2026 | Nothing the customer asked for makes it strictly necessary. Do not build the tag |
| A rosary bought as a gift | Arguably data revealing religious beliefs; sensitive for certain once it feeds a “religious buyers” segment | Fulfill the order; keep it out of segments and ad events |
| A phone’s location, used to find the nearest pickup point | Precise geolocation within 1,750 feet: sensitive | Use it while the pickup needs it; never sell it |
| An account the store knows belongs to a 12-year-old | Personal data of a child: sensitive | Parental consent that meets the federal COPPA rules satisfies the parental-consent duty (§14–4703(c)); no targeted ads or sale for anyone the store should know is under 18 |
The practical danger for a store is rarely a bad decision in the database. It is the plumbing. Advertising and analytics tags usually send the page address, the product identifier and often the product name to the ad platform with every view, add-to-cart and purchase, and many stores also send a hashed email address so the platform can match the buyer. On a sensitive product, that is sharing sensitive data with a third party for something the customer never asked for. On most stores it is also a tag-manager setting, and it is the first change I would make in any store that sells health products: flag the products, and keep every flagged one out of every event, every audience and every export. If you run the online front store of a pharmacy, read this section twice; we wrote about the rest of an independent pharmacy’s software in a separate post.
Location has its own rules. Section 14–4704 bans geofences within 1,750 feet of a mental health facility or a reproductive or sexual health facility that are used to identify, track or collect data from consumers, or to send them notifications, about their consumer health data. Chapter 874 widened what counts as precise geolocation to the location of “a consumer, a mobile device, or a vehicle” within that same radius. A “find the nearest pickup point” feature that reads the customer’s phone is handling precise geolocation, and so is a tow operator’s record of the GPS point where a customer’s car was picked up; we looked at the rest of that trade in our towing post. A food truck’s own location history, which mattered so much in the food truck post, is the business’s data rather than a consumer’s, and stays outside it.
Stores that sell to children have a second Maryland law to think about, the Maryland Kids Code of 2024, but it reaches only businesses that meet one of three tests: more than $25 million in annual revenue, adjusted for inflation; buying, receiving, selling or sharing the data of 50,000 or more consumers, households or devices a year; or earning at least half their revenue from selling data (§14–4801). Most small Baltimore stores sit outside it. MODPA’s under-18 rules are the ones that reach them.
What the law asks your store’s software to do
Stripped of its legal structure, MODPA reads like a specification. Each duty becomes a feature, a setting or a record somewhere in a store’s systems, and the whole thing is easier to see that way than section by section.
Collection is a form-design rule
“A controller shall: (i) Limit the collection of personal data to what is reasonably necessary and proportionate to provide or maintain a specific product or service requested by the consumer to whom the data pertains” — Md. Commercial Law §14–4707(b)(1)
In a store, the specific product or service a customer requests is the order. A shipping address is necessary for a parcel. A phone number is necessary if the courier needs it and not otherwise. A date of birth is not necessary to sell a candle, although it may be proportionate to a birthday discount the customer chose to join, which is a separate service they asked for. A gender field at checkout is necessary for almost nothing. Maryland ties the data to what the consumer asked for, where most states tie it to whatever purposes the business discloses, and that difference is why the law is so often called the strictest in the country. For anything beyond the order, the same section adds that processing personal data for a purpose that is neither reasonably necessary to nor compatible with the purposes you disclosed requires the customer’s consent (§14–4707(a)(8)). In practice, the checkout asks for what the order needs, and everything else becomes an optional field with its purpose written beside it.
Consent has a definition, and a banner can fail it
Where the law needs consent, it defines it: a clear affirmative act signifying a consumer’s freely given, specific, informed and unambiguous agreement to a particular purpose. It lists what does not count: accepting general terms of use that bury the processing among unrelated things; hovering over, muting, pausing or closing a piece of content; and agreement obtained through dark patterns, a term the statute stretches to include any practice the Federal Trade Commission calls one. Withdrawing consent must be at least as easy as giving it, and processing must stop within 30 days of the request (§14–4707(b)). For a store, that turns into something concrete: a consent is a record with a purpose, a timestamp and the exact wording the customer saw, and the control to withdraw it sits one click away wherever the original checkbox was.
The opt-out link, and the signal from the browser
A covered store has to let customers opt out of targeted advertising, the sale of their data and certain automated profiling, and has to say clearly if it does any of those things. The statute’s drafting on how to do that is unusual. Section 14–4707(f)(3) lists two methods a controller “may utilize”: a clear and conspicuous link to an opt-out page, and, with the date “on or before October 1, 2025” attached, honoring an opt-out preference signal sent by a browser or device. Separately, §14–4706 lets a consumer appoint an authorized agent to opt out for them, and says how:
“A consumer may designate an authorized agent by an Internet link or a browser setting, browser extension, global device setting, or other similar technology, indicating a consumer’s intent to opt out of the processing of the consumer’s personal data.” — Md. Commercial Law §14–4706(a)(2)
Add §14–4707(g)(2), which says a controller that recognizes signals approved by other states is in compliance, and most compliance guides read the three provisions together as a requirement to honor Global Privacy Control, the browser signal that Brave and DuckDuckGo send by default and Firefox offers as a setting. That is how I would build, because it costs almost nothing. The browser sends a Sec-GPC: 1 header with each request, and a store can treat it as an opt-out on the server before any advertising tag loads, without asking the visitor to log in. The one wrinkle is loyalty programs: if the signal conflicts with a customer’s membership in a bona fide loyalty or discount program, §14–4707(g)(1) lets the store ask the customer which choice they meant.
If your store runs on Shopify, much of this is a setting rather than a project. Shopify’s help center says that when a visitor’s browser sends the GPC header, Shopify treats it as an opt-out of the sale or sharing of data and of targeted advertising, by Shopify and by third parties, but only for visitors in regions where the merchant uses a data sharing opt-out page. The catch is in that last clause. The merchant has to set up the opt-out page for the relevant US regions, and Shopify does not switch its cookie banner on in the US by default. If you are on Shopify and below the line, ten minutes in those settings is time well spent, and a good reason to stay where you are.
Rights requests run on a clock
Covered stores must answer customers who ask to confirm and see their data, correct it, delete it, take a portable copy, learn which categories of third parties received it, or opt out. The statute is specific about the mechanics, and each one is a workflow someone has to own.
| What happens | The clock | Where |
|---|---|---|
| Respond to a consumer’s request | 45 days | §14–4705(e)(2)(i) |
| Extend, if you tell the consumer why within the first 45 days | 45 more days | §14–4705(e)(2)(ii) |
| Tell the consumer you will not act, and how to appeal | Within 45 days | §14–4705(e)(3) |
| Decide an appeal, in writing, with reasons | 60 days | §14–4705(f)(3) |
| Answer requests free of charge | Once in any 12 months | §14–4705(e)(4) |
| Stop processing after consent is withdrawn | 30 days at most | §14–4707(b)(2) |
| Cure a violation after a notice from the Division, where one is offered | At least 60 days, for violations through 1 April 2027 | §14–4714 |
| The window for the 35,000 count | The preceding calendar year | §14–4702 |
| Data protection assessments | Processing on or after 1 October 2025 | §14–4710(h) |
| Processing the law reaches at all | On or after 1 April 2026 | Chapters 454 and 455 of 2024, uncodified |
| The radius that makes a location precise, and the geofence ban | 1,750 feet | §§14–4701(x) and 14–4704(3) |
Four of the details are easy to miss, and all four are software. A store may not make someone create an account to exercise a right, though it may ask an existing customer to use theirs. It does not have to authenticate an opt-out at all. When it deletes data it bought or received from somewhere else, it may keep a record of the deletion request and the minimum needed to make sure the data stays deleted, which is a suppression list by another name. And when it denies an appeal, it has to give the customer an online way to complain to the Consumer Protection Division.
A contract with every processor
Every vendor that processes customer data on a store’s behalf, from the platform and the email tool to the SMS service, the shipping app, the reviews widget and the helpdesk, needs a binding contract setting out the processing instructions, the nature and purpose of the processing, the type of data, the duration and both parties’ rights and obligations. The contract must commit the vendor to confidentiality and security, to deleting or returning the data at the end, to letting the store object before a subcontractor is brought in, and to cooperating with reasonable assessments (§14–4708). Most established vendors publish a data processing addendum that covers it. The work for a small store is knowing which vendors hold what, and keeping the list.
Assessments for the risky parts
Targeted advertising, selling data, processing sensitive data and certain kinds of profiling are what the statute calls processing activities that present a heightened risk of harm to a consumer, and each needs a documented data protection assessment that weighs the benefits against the risks, “including an assessment for each algorithm that is used” (§14–4710(b)). The assessments are confidential, the Division can demand them in an investigation, and one assessment can cover a set of similar operations. A store that retargets visitors with Meta and Google ads has at least one of these to write. A store that also sells health products has two.
What the privacy notice has to say
The notice has six required parts (§14–4707(d)): the categories of personal data processed, including sensitive data; the purposes; how to exercise rights, appeal a decision and withdraw consent; the categories of third parties, described well enough to understand what they do; the categories of data shared with them; and an active email address or other online way to reach the business. Selling data or processing it for targeted advertising must be disclosed clearly and conspicuously, together with the way to opt out. A notice generated from a template and never checked against what the store actually does is the most common way this goes wrong, because the notice is a promise, and the Consumer Protection Act has always treated a misleading promise as a deceptive practice.
One more duty sits alongside all of this. MODPA requires reasonable administrative, technical and physical security for personal data, and Maryland’s older Personal Information Protection Act governs what happens when that fails: affected Marylanders must be notified no later than 45 days after the business discovers a breach, and the Attorney General’s office must be told as well.
The e-commerce half: what the tools count, and what they cost
Most small stores meet MODPA through a product: a consent banner app, a cookie scanner, a privacy-policy generator. They are useful and mostly inexpensive, and I would recommend one to most stores that advertise. But look at what they meter, because none of them meters what the law counts. These are the published prices as of 11 September 2026.
| Tool | What it counts | Published prices |
|---|---|---|
| CookieYes | Pageviews a month, per domain | Free up to 5,000; $10 a month for 100,000; $25 for 300,000; $55 unlimited; $0.30 per 1,000 extra pageviews on the two middle plans |
| iubenda | Pageviews a month, per site | $5.99 a month for 25,000, $24.99 for 50,000 and $99.99 for 150,000, billed yearly; €0.05 per 1,000 extra pageviews |
| Termly | Consent-banner views a month, per website | Free up to 10,000; $10 a month for 50,000 and $15 unlimited, billed annually ($14 and $20 billed monthly) |
| Ketch | Average monthly unique users across web and apps | Free up to 5,000; $150 a month for 30,000; from $499 a month for 100,000, billed annually |
| Secure Privacy | Domains | Free; $15, $59 and $249 a month per domain |
| Consentmo (Shopify app) | Stores | Free; $10, $37 and $64 a month |
| Pandectes (Shopify app) | Stores | Paid plans at $9, $29 and $49 a month |
Seven tools, five meters: pageviews, banner views, monthly unique users, domains and stores. Cookiebot adds a sixth, sizing its plans by sessions, which it defines as website visits. The law’s unit is Maryland residents per calendar year, and no invoice from a consent vendor will tell you whether you have crossed it. That is not a criticism of the vendors. A banner cannot know where a visitor lives or how many times the same person came back, and it was never meant to.
To see how the meters behave, I priced two model stores from the published plans. Store A has 30,000 pageviews and 9,000 unique visitors a month, about what a busy neighborhood shop might see. Store B has 150,000 pageviews and 45,000 unique visitors, a regional brand.
| Tool | Store A, a month | Store B, a month | How it gets there |
|---|---|---|---|
| CookieYes | $10 | $25 | A fits Basic’s 100,000 pageviews. B is Basic plus 50,000 extra pageviews at $0.30 per 1,000: $10 + $15 = $25, exactly the price of Pro |
| iubenda | $5.99 + €0.25 | $5.99 + €6.25 | Essentials includes 25,000 pageviews; the extra 5,000 and 125,000 cost €0.05 per 1,000 |
| Ketch | $150 | from $499 | A is over the free 5,000 users and inside Starter’s 30,000; B is over 30,000 and inside Plus |
| Consentmo | $0 to $64 | $0 to $64 | A flat fee per store; traffic does not change it |
Two results. The first is a small curiosity: on CookieYes, Store B pays exactly $25 a month whether it buys the Pro plan or pays overage on Basic, because 150,000 pageviews is precisely where the two lines cross. The second matters more. For a local store like Store A, the consent tool is the cheapest part of complying, somewhere between nothing and $150 a month on these plans, and the part that scales with traffic is the part that matters least. The expensive parts do not scale with traffic at all: answering a deletion request across five systems, keeping sensitive products out of ad events, writing the assessments, knowing which vendor holds what. Those are properties of the store’s software, not of its banner.
What it costs to build it in
We publish four fixed prices and do not move them from client to client. Here is how the work above maps onto them. A Maryland business buying any of them pays Maryland’s 3% tax on data and information technology services on top, as it would with any studio.
| Package | The privacy work in it | Price | Maryland 3% | Total |
|---|---|---|---|---|
| Prototype Sprint | A one-week map of every system that holds customer data, and a working prototype of the request and consent flows | $3,500 | $105.00 | $3,605.00 |
| Online Store | A store whose checkout asks only for what the order needs, with consent records, server-side GPC handling, sensitive-product flags kept out of ad events, and a request form that needs no account | from $6,000 | from $180.00 | from $6,180.00 |
| Custom App / Internal Tool | A privacy back office: one queue for access, correction and deletion requests across the store, email, helpdesk and order database, with the 45-day clock, extensions and the appeal record | from $12,000 | from $360.00 | from $12,360.00 |
| Operations System | Retention and deletion rules that run across orders, inventory and fulfillment records, with the suppression list the statute allows | from $12,000 | from $360.00 | from $12,360.00 |
The detail that matters more than the totals is timing. Privacy work is far cheaper at the start of a build than after it. A checkout that never collected a date of birth has nothing to delete. A catalog that carries a sensitivity flag from the first day never sends a pregnancy test to an ad platform. Retrofitting the same rules into a store that has run on apps and exports for five years is where the cost lives, and it is one more reason we fix the scope in writing before anyone writes code, which we explained in why we fixed-price everything.
What we would build, and what we would leave alone
For a store comfortably below the line, say a Shopify shop with a few thousand Maryland customers and a modest list, the honest advice is to stay on the platform, configure its privacy settings, add a consent tool from the table above if you run advertising, write down your vendors and get on with your week. MODPA does not apply to you yet, and the habits it asks for cost almost nothing to adopt early. We would rather tell you that on a call than sell you a build.
For a store near the line or over it, especially one selling anything health-related, the work is a thin layer rather than a rebuild: a map of where customer data lives, a request queue with its clocks, a suppression list, tag rules that keep flagged products out of advertising, and a consent log. That layer is software, and it is the kind of thing we build quickly. For a new store, we would put the rules into the store itself from the first commit; we walked through a whole store build, Friday to Sunday, and these rules add surprisingly little to it. Restaurants face the same questions with a loyalty program attached, which we covered in our online ordering post. And if you are still deciding whether to build at all, our plain guide to custom versus SaaS versus no-code is the place to start.
What I would check this month
If you run an online store in Maryland, this is the whole checklist, and it is the only list in this article.
- Count people, not customers. Add up the Maryland residents on your email and SMS lists and in your accounts, loyalty program and order history for 2026 so far, and, on the cautious reading, the visitors your analytics and ad tools can recognize. That number decides whether the law applies to you in 2027.
- Read your checkout like an auditor. Go field by field and ask whether the order needs it. Remove what it does not, and give every optional field its own stated purpose.
- Flag your sensitive products. If you sell anything health-related, religious or meant for children, mark those products and keep them out of ad events, audiences and exports. Delete any segment that guesses at a sensitive trait.
- Honor the browser signal. Add an opt-out link, treat Global Privacy Control as an opt-out, and if you are on Shopify, set up the data sharing opt-out page for US regions.
- Write down who holds what. List every vendor that touches customer data with its processing agreement, set up one inbox for privacy requests with the 45-day clock, and draft the assessment for your advertising before 1 April 2027, when the cure period ends.
Who we are
We are a two-founder studio in Baltimore. We build custom software at a fixed price, you work directly with the people who write the code, and you own everything when we finish. Most of this blog goes one Baltimore trade at a time, from restaurants and pharmacies to nonprofits and tow operators, and nearly every one of those trades keeps customer data somewhere this law will eventually reach. Like our guide to Maryland’s tech tax, this post is the one those trade posts can point to. If you are weighing custom software for the first time, start with our guide to custom software development in Baltimore.
I work on engineering and AI at the studio, which in practice means I am the one who turns a phrase like “strictly necessary to provide or maintain a specific product or service requested by the consumer” into a field, a flag and a rule in somebody’s database. If you would like us to look at your store with you, the call is free, and we will tell you honestly if the answer is to keep what you have. We are not lawyers, and on the legal question your attorney gets the last word.
Common questions about Maryland’s Online Data Privacy Act
Does the Maryland Online Data Privacy Act apply to my small business?
It applies if you conduct business in Maryland or target products or services to Maryland residents, and in the previous calendar year you controlled or processed the personal data of at least 35,000 Maryland residents, not counting data processed solely to complete a payment transaction, or of at least 10,000 residents while earning more than 20% of your gross revenue from selling personal data. There is no revenue threshold, so a small business with a large audience is covered, and a store outside Maryland that sells to Marylanders is covered once it crosses the line. Whether it applies to you in 2027 depends on the data you handle during 2026.
What counts toward MODPA’s 35,000-consumer threshold?
Maryland residents acting in a personal capacity whose personal data you collected, stored, used, shared, analyzed, changed or deleted during the preceding calendar year. That includes customers, account holders, email and SMS subscribers and loyalty members, whether or not they bought anything. Business contacts and employees do not count, and data processed solely to complete a payment is excluded. Whether website visitors known only by a cookie or an advertising identifier count is not settled; the cautious reading counts any visitor your tools can recognize again.
When did MODPA take effect?
The law took effect on 1 October 2025, and it does not apply to processing of personal data that happened before 1 April 2026. For violations that occur on or before 1 April 2027, the Consumer Protection Division may give a business notice and at least 60 days to cure before bringing an enforcement action. The amendments in Chapter 874 of 2026 took effect on 1 July 2026.
What does “strictly necessary” mean under MODPA?
It is the standard for sensitive data. Under section 14–4707(a)(1) a business may collect, process or share sensitive data only where that is strictly necessary to provide or maintain a specific product or service the consumer requested, and under section 14–4707(a)(2) it may never sell sensitive data. Unlike most state privacy laws, Maryland’s has no consent exception to either rule. For all other personal data the standard is looser: collection must be limited to what is reasonably necessary and proportionate to provide or maintain the product or service requested. The statute does not define either phrase further, and neither has been tested in a published enforcement action that I am aware of.
Does MODPA require businesses to honor Global Privacy Control?
In practice, yes. Section 14–4707(f)(3) lists honoring an opt-out preference signal sent by a browser or device as one of the ways a consumer may opt out of targeted advertising and the sale of personal data, section 14–4706 lets a consumer appoint an authorized agent through a browser setting, browser extension or global device setting, and a business that recognizes signals approved by other states is treated as compliant. Most compliance guides read these provisions together as a requirement to honor Global Privacy Control, and it is inexpensive to do: treat the Sec-GPC header as an opt-out before any advertising tag loads.
What did Maryland change in its privacy law in 2026?
Chapter 874 of 2026, House Bill 711, became law without the governor’s signature and took effect on 1 July 2026. Data a business infers from other personal data to indicate a sensitive trait is now sensitive data. Precise geolocation now covers the location of a consumer, a mobile device or a vehicle within 1,750 feet. A business may not knowingly sell personal data to a federal, State or local governmental unit that engaged in or supported civil immigration enforcement in the preceding six months, and the law’s protection for complying with subpoenas and cooperating with law enforcement no longer covers requests from such units, or subpoenas derived from them, unless a valid warrant is presented. Bills that would have changed the collection standard did not pass.
What are the penalties for violating MODPA?
A violation is an unfair, abusive or deceptive trade practice under the Maryland Consumer Protection Act, enforced by the Attorney General’s Consumer Protection Division. That Act allows civil penalties of up to $10,000 for each violation and up to $25,000 for each repetition of the same violation, and its misdemeanor provisions also apply. Consumers cannot sue for damages under MODPA, because the law excludes the Consumer Protection Act’s private-action section, section 13–408.
Do nonprofits have to comply with MODPA?
Yes, if they cross the threshold. MODPA exempts only a nonprofit that processes or shares personal data solely to help law enforcement investigate insurance-related crime or fraud, or to help first responders during catastrophic events. Other nonprofits are covered like any business, unlike under Virginia’s law, which exempts nonprofit organizations. A Baltimore nonprofit with a large donor, volunteer or email list should count its Maryland contacts the same way a store would.