What does Maryland's MODPA data minimization rule require?
Maryland requires a controller or processor to limit collection of personal data to what is reasonably necessary and proportionate to provide or maintain a specific product or service the consumer requested. Unlike most state laws, that standard is tied to the consumer's request rather than to the purposes disclosed in the business's privacy notice.
Applies to: Controllers and processors subject to the Maryland Online Data Privacy Act, meaning businesses that operate in Maryland or target its residents and meet the Act's consumer-count or data-sale thresholds.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanMaryland wrote a data minimization rule that most compliance programs are not built for. The difference is small on the page and large in practice.
The text
Md. Code, Com. Law section 14-4607(b)(1) says a controller or processor shall limit the collection of personal data to what is reasonably necessary and proportionate to provide or maintain a specific product or service requested by the consumer to whom the data pertains.
Read that against the more common formulation. Virginia, Colorado, and most of the states that followed them limit collection to what is adequate, relevant, and reasonably necessary in relation to the purposes for which the data is processed, as disclosed to the consumer. Under those laws the disclosed purpose sets the boundary, so a business can lawfully widen collection by widening its privacy notice.
Maryland removes that lever. The measure is the specific product or service the consumer requested. A privacy notice that lists analytics, personalization, and partner marketing does not make collection for those things necessary to deliver what the consumer asked for.
The two duties that travel with it
Section 14-4607(b)(1) imposes three obligations in one sentence, and the minimization rule is only the first.
The second requires a controller or processor to establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data appropriate to the volume and nature of the personal data at issue. The proportionality idea repeats here: the standard scales with how much data you hold and how sensitive it is.
The third requires an effective mechanism for a consumer to revoke consent that is at least as easy as the mechanism by which the consumer provided consent. A one-click consent banner paired with an email-us-to-withdraw process does not satisfy that.
Sensitive data gets a stricter gate
Section 14-4607(a) prohibits a controller or processor from collecting, processing, or sharing sensitive data concerning a consumer except where the collection or processing is strictly necessary to provide or maintain a specific product or service requested by the consumer, and unless the controller obtains the consumer's consent. The same subsection separately prohibits selling sensitive data.
Note the shift in wording. General personal data is governed by reasonably necessary and proportionate. Sensitive data is governed by strictly necessary, and consent does not substitute for that test, it stacks on top of it.
When this started applying
The Maryland Online Data Privacy Act of 2024 was passed as House Bill 567 and approved by the Governor on May 9, 2024 as Chapter 454. The General Assembly's record for the bill gives its effective date as October 1, 2025.
What this changes in practice
Three things tend to break under this standard. Prefilled optional form fields that no one needs to deliver the service. Analytics and advertising SDKs that collect device and behavioral data on the theory that the privacy notice mentions them. And enrichment, where a business buys additional attributes about people who requested something narrow.
The remedy is unglamorous. Inventory what you collect field by field, name the specific product or service each field supports, and remove what cannot be justified. That inventory is also the artifact you will want if the Attorney General ever asks.
Next step
Maryland is one of several states with a comprehensive privacy law, and the thresholds differ from the obligations. The free 2-minute Obligation Scan tells you which US state privacy laws apply to your business and what each requires. The Maryland MODPA overview covers who the Act applies to, and the state threshold comparison shows how Maryland's triggers compare with the rest.
Compliance checklist
- Map every field you collect to the specific product or service the consumer requested, and delete or stop collecting anything you cannot tie to one.
- Stop relying on a broadly worded privacy notice to justify collection, because Maryland measures necessity against the consumer's request, not against your disclosed purposes.
- Treat sensitive data as off limits unless collection or processing is strictly necessary to provide or maintain the product or service the consumer requested, and you have the consumer's consent.
- Maintain reasonable administrative, technical, and physical safeguards that fit the volume and nature of the personal data you hold, as section 14-4607(b)(1)(ii) requires.
- Give consumers a revocation mechanism that is at least as easy as the mechanism they used to give consent in the first place.
Sources
- Chapter 454 (House Bill 567), Maryland Online Data Privacy Act of 2024, 2024 Laws of Maryland, Maryland General Assembly
- HB0567 legislation details, 2024 Regular Session (status, chapter, and effective date), Maryland General Assembly
Last verified: 2026-08-20
Informational, not legal advice.