Consumer Data Privacy

Maryland Consumer Data Privacy Law: Thresholds, Consumer Rights & Deadlines

What Maryland’s consumer data privacy law requires, maintained by Stauss PLLC. Last reviewed July 2026.

What You Need to Know

Maryland's law sets a low applicability threshold of 35,000 consumers. Its core feature is data minimization: controllers must limit personal data collection to what is reasonably necessary and proportionate to provide the requested product or service, and limit sensitive data collection, processing, and sharing to what is "strictly necessary" for that purpose. Selling sensitive data is prohibited outright. Minors get heightened protection — controllers cannot use personal data for targeted advertising or sell it if they knew or should have known the consumer is under 18. The law also has notable anti-discrimination language, a broad biometric data definition, third-party sharing provisions, and a data protection assessment requirement that extends to algorithms. In 2026, the law was amended to modify the definition of sensitive data to include “data inferred by a controller based on personal data that, alone or in combination with other data, is used to indicate” any category of sensitive data.

Official law text
Who the law applies to
ThresholdRequirement
Annual gross revenueN/A
Consumers whose data is processed35,000 consumers 0.56% of state's 6.18 million population
Revenue from sale of personal dataDerives more than 20% of gross revenue from sale of personal data and controls or processes personal data of not less than 10,000 consumers.
Consumer rights under Maryland's law15
RightProvided?
KnowYes
AccessYes
Obtain list of third parties to which personal data was disclosed
noteConsumers have the right to obtain a list of the categories of third parties to which a controller has disclosed the consumer’s personal data or a list of the categories of third parties to which the controller has disclosed any consumer’s personal data if the controller does not maintain a list of third parties in a format specific to the consumer.
Partial
Data portabilityYes
DeleteYes
Correct inaccuraciesYes
Not be discriminated against for exercising rightsYes
Opt-out of saleYes
Opt-out of targeted advertising/sharingYes
Opt-out of certain types of profilingYes
Opt-out of ADMTNo
Recognize opt-out signals
noteMaryland states that a controller may use a link or recognize opt-out preference signals.
Partial
Revoke consentYes
Not process data in discriminatory mannerYes
AppealYes

Tracking Maryland’s privacy law? We write about it as the law changes.

Subscribe →
Categories treated as sensitive data11
  • Racial or ethnic origin
  • National origin
  • Religious beliefs
  • Sexual orientation
  • Sex life
  • Status as transgender or nonbinary
  • Citizenship or immigration status
  • Genetic or biometric data
    noteDelaware, Maryland, and Oregon's definitions of sensitive data do not state that biometric data must be used to identify individuals. However, this requirement is found in each law's definition of biometric data.
  • Personal data of known child
  • Precise geolocation
    noteConnecticut, Maryland, Oregon, and Virginia ban the sale of precise geolocation data.
  • Consumer health data
How sensitive data must be treated4
  • Collection/Processing Must be Strictly Necessary to Maintain Product or Service Requested by Consumer
  • Cannot Sell Sensitive Data
  • Cannot Sell Precise Geolocation Data
  • Conduct Data Protection or Risk Assessment
Requirements for minors' data1
  • Cannot sell personal data or process personal data for targeted advertising for children under 18
Activities that trigger a risk or impact assessment4
  • Targeted advertising (“sharing”)
  • Sale of personal data
  • Processing of sensitive data
  • Processing personal data for purposes of profiling where it presents reasonably foreseeable risk of unfair or deceptive treatment of, or unlawful disparate impact on, consumers; financial, physical, or reputational injury to consumers; physical or other intrusion upon the solitude or seclusion, or the private affairs or concerns, of consumers, where such intrusion would be offensive to a reasonable person; other subject injury to consumers
Other notable provisions10
  • Definition of “Sale” Includes “Other Valuable Consideration”
  • Applies to Nonprofits
  • Data Processing Agreements
  • Privacy Policy
  • Implement Reasonable Data Security Measures
  • Duty to Avoid Secondary Use
  • Data Minimization
    noteIn addition to limiting the collection of sensitive data, Maryland states that a controller shall “limit the collection of personal data to what is reasonably necessary and proportionate to provide or maintain a specific product or service requested by the consumer to whom the data pertains.” This is more restrictive than other state laws.
  • Attorney General Enforcement
  • Right to Cure
    note60 day right to cure that sunsets April 1, 2027.
  • Rulemaking
    noteMaryland’s law does not itself authorize rulemaking. However, Maryland Code § 13-205 allows the Division of Consumer Protection to engage in permissive rulemaking “to effectuation the purposes of this subtitle, including rules, regulations, or standards which further define specific unfair or deceptive trade practices.”
Key dates2
DateWhat happens
October 1, 2025Maryland's consumer data privacy law takes effect
April 1, 2027Maryland's 60-day right to cure sunsets

Questions about Maryland’s privacy law?

Stauss PLLC advises companies on state privacy, AI, and data broker compliance.

Contact Stauss PLLC

Follow Maryland’s privacy law

Our analysis, by email, as the law moves.

Subscribe

This page is provided for general informational purposes only, is not legal advice, and does not create an attorney-client relationship. State laws change frequently; coverage reflects this tool’s most recent update. Contact Stauss PLLC to confirm how these requirements apply to your organization.