Maryland · Online Data Privacy Act

Run MODPA — the strictest of the state privacy acts

Maryland broke from the template. Data minimization is a hard limit that consent cannot cure, selling sensitive data is prohibited outright, and minors get protections no other state matched. AccessPoint runs the regime as written.

Maryland — MODPA at a glance

Rights deadline
45 days, extendable once by a further 45 days on notice
Appeal
An internal appeal of a refusal, answered within the statutory window
Minimization
Collection limited to what is reasonably necessary — consent does not cure an excess
Sensitive data
Sale prohibited; processing limited to what is strictly necessary
Minors
Heightened protections on targeted advertising and sale
Languages
English

Built for Maryland — MODPA

One platform for the whole access-and-privacy mandate, pre-configured for this regime and running in your own Microsoft 365 tenant.

Minimization as a hard limit

Most state acts let consent unlock additional collection. Maryland does not — collection must be reasonably necessary and proportionate to the specific product or service requested, whatever the consumer agrees to. That makes the recorded justification for each purpose the central artefact.

Sensitive data, not for sale

MODPA prohibits selling sensitive data outright rather than gating it behind consent. Record what categories you hold, why, and on what basis — so the prohibition is evidenced rather than assumed.

Minors' protections

Maryland extended protections to minors well beyond the other state acts. Record the age-related determinations and the controls applied where processing touches young people.

Rights and appeals

Access, deletion, correction, portability, and opt-outs on the 45-day clock, with a refusal appealable internally and the appeal tracked as its own stage.

Data protection assessments

Run assessments for higher-risk processing as full cases — questionnaire, risks with owners, mitigations, and a dated sign-off an Attorney General inquiry can read.

In your own tenant

Consumer personal information stays inside your own Microsoft 365 and Azure tenant — no third-party privacy cloud holding the very data the requests are about.

Consent is not a cure

Maryland removed the escape hatch every other state left open.

The state privacy acts mostly follow a bargain: collect what you disclose, and where the processing is sensitive, get consent. Maryland changed the terms. Under MODPA, collection must be limited to what is reasonably necessary and proportionate to the specific product or service the consumer requested — and consent does not unlock more. Sensitive data may not be sold at all, and processing of it is confined to what is strictly necessary. For organizations whose compliance programs are built around consent flows and disclosure notices, this is a different question entirely: not what did you tell people, but what did you decide you needed, and can you show the reasoning. AccessPoint records purposes, data categories, and the justification behind them in a register, and links each to the assessment that approved it.

Necessary and proportionate A justification recorded per purpose, not a consent banner.
Sensitive data ring-fenced Sale prohibited; strict-necessity processing recorded.
Assessments that decide The approval trail behind each higher-risk purpose.

Configured out of the box

Installing the us-md-mmdpa jurisdiction pack seeds your tenant with everything this regime needs — a starting point you can adjust, not a lock-in.

Related guide: FOI Workflow Quick Check
  • MODPA as the legal-authority spine
  • The 45-day rights clock with its single 45-day extension and the appeal stage
  • Request types for access, deletion, correction, portability, and the opt-out rights
  • A purpose and data-category register carrying the necessity and proportionality justification
  • Sensitive-data handling with the sale prohibition and strict-necessity limits recorded
  • Minors' processing determinations and the heightened controls applied
  • Data protection assessments for targeted advertising, sale, sensitive data, and profiling
  • Refusal grounds cited on the response, with Attorney General complaint information on a denied appeal

Maryland — MODPA Questions

What makes MODPA stricter than the other state acts?

Three things. Data minimization is a substantive limit rather than a disclosure duty — collection must be reasonably necessary and proportionate to the product or service requested, and consent does not cure an excess. Selling sensitive data is prohibited outright rather than gated behind consent. And minors receive protections beyond what other states adopted.

Can we run MODPA alongside the other state acts?

Yes. Most organizations install the multi-state consumer privacy pack for the Virginia-derived states and add MODPA for Maryland, since Maryland's substantive limits genuinely differ. Both run on one platform, with the governing law recorded on each request.

How does AccessPoint evidence data minimization?

Through a register of purposes and the data categories each one relies on, with the necessity and proportionality justification recorded against it and linked to the assessment that approved the processing. That converts minimization from a claim into a dated record showing what was decided and on what basis.

Where does consumer personal information reside?

Entirely within your own Microsoft 365 and Azure tenant. Requests, the personal information gathered to answer them, and the audit history never leave your control — no third-party cloud and no vendor access.

Run MODPA in Your Own Tenant

Try AccessPoint free for 30 days, configured for Maryland's online data privacy regime. No credit card required.

Start Free Trial