Consumer Data Privacy
Maryland Consumer Data Privacy Law: Thresholds, Consumer Rights & Deadlines
What Maryland’s consumer data privacy law requires, maintained by Stauss PLLC. Last reviewed July 2026.
What You Need to Know
Maryland's law sets a low applicability threshold of 35,000 consumers. Its core feature is data minimization: controllers must limit personal data collection to what is reasonably necessary and proportionate to provide the requested product or service, and limit sensitive data collection, processing, and sharing to what is "strictly necessary" for that purpose. Selling sensitive data is prohibited outright. Minors get heightened protection — controllers cannot use personal data for targeted advertising or sell it if they knew or should have known the consumer is under 18. The law also has notable anti-discrimination language, a broad biometric data definition, third-party sharing provisions, and a data protection assessment requirement that extends to algorithms. In 2026, the law was amended to modify the definition of sensitive data to include “data inferred by a controller based on personal data that, alone or in combination with other data, is used to indicate” any category of sensitive data.
Official law text
Who the law applies to
| Threshold | Requirement |
|---|---|
| Annual gross revenue | N/A |
| Consumers whose data is processed | 35,000 consumers 0.56% of state's 6.18 million population |
| Revenue from sale of personal data | Derives more than 20% of gross revenue from sale of personal data and controls or processes personal data of not less than 10,000 consumers. |
Consumer rights under Maryland's law15
| Right | Provided? |
|---|---|
| Know | Yes |
| Access | Yes |
Obtain list of third parties to which personal data was disclosednoteConsumers have the right to obtain a list of the categories of third parties to which a controller has disclosed the consumer’s personal data or a list of the categories of third parties to which the controller has disclosed any consumer’s personal data if the controller does not maintain a list of third parties in a format specific to the consumer. | Partial |
| Data portability | Yes |
| Delete | Yes |
| Correct inaccuracies | Yes |
| Not be discriminated against for exercising rights | Yes |
| Opt-out of sale | Yes |
| Opt-out of targeted advertising/sharing | Yes |
| Opt-out of certain types of profiling | Yes |
| Opt-out of ADMT | No |
Recognize opt-out signalsnoteMaryland states that a controller may use a link or recognize opt-out preference signals. | Partial |
| Revoke consent | Yes |
| Not process data in discriminatory manner | Yes |
| Appeal | Yes |
Categories treated as sensitive data11
- Racial or ethnic origin
- National origin
- Religious beliefs
- Sexual orientation
- Sex life
- Status as transgender or nonbinary
- Citizenship or immigration status
- Genetic or biometric data
note
Delaware, Maryland, and Oregon's definitions of sensitive data do not state that biometric data must be used to identify individuals. However, this requirement is found in each law's definition of biometric data. - Personal data of known child
- Precise geolocation
note
Connecticut, Maryland, Oregon, and Virginia ban the sale of precise geolocation data. - Consumer health data
How sensitive data must be treated4
- Collection/Processing Must be Strictly Necessary to Maintain Product or Service Requested by Consumer
- Cannot Sell Sensitive Data
- Cannot Sell Precise Geolocation Data
- Conduct Data Protection or Risk Assessment
Requirements for minors' data1
- Cannot sell personal data or process personal data for targeted advertising for children under 18
Activities that trigger a risk or impact assessment4
- Targeted advertising (“sharing”)
- Sale of personal data
- Processing of sensitive data
- Processing personal data for purposes of profiling where it presents reasonably foreseeable risk of unfair or deceptive treatment of, or unlawful disparate impact on, consumers; financial, physical, or reputational injury to consumers; physical or other intrusion upon the solitude or seclusion, or the private affairs or concerns, of consumers, where such intrusion would be offensive to a reasonable person; other subject injury to consumers
Other notable provisions10
- Definition of “Sale” Includes “Other Valuable Consideration”
- Applies to Nonprofits
- Data Processing Agreements
- Privacy Policy
- Implement Reasonable Data Security Measures
- Duty to Avoid Secondary Use
- Data Minimization
note
In addition to limiting the collection of sensitive data, Maryland states that a controller shall “limit the collection of personal data to what is reasonably necessary and proportionate to provide or maintain a specific product or service requested by the consumer to whom the data pertains.” This is more restrictive than other state laws. - Attorney General Enforcement
- Right to Cure
note
60 day right to cure that sunsets April 1, 2027. - Rulemaking
note
Maryland’s law does not itself authorize rulemaking. However, Maryland Code § 13-205 allows the Division of Consumer Protection to engage in permissive rulemaking “to effectuation the purposes of this subtitle, including rules, regulations, or standards which further define specific unfair or deceptive trade practices.”
Key dates2
| Date | What happens |
|---|---|
| October 1, 2025 | Maryland's consumer data privacy law takes effect |
| April 1, 2027 | Maryland's 60-day right to cure sunsets |
Questions about Maryland’s privacy law?
Stauss PLLC advises companies on state privacy, AI, and data broker compliance.
Contact Stauss PLLCThis page is provided for general informational purposes only, is not legal advice, and does not create an attorney-client relationship. State laws change frequently; coverage reflects this tool’s most recent update. Contact Stauss PLLC to confirm how these requirements apply to your organization.
