Can you sell sensitive data in Maryland?
No. Maryland flatly prohibits the sale of sensitive data, with no consent exception. Collecting, processing or sharing sensitive data is also barred unless it is strictly necessary to provide the product or service the consumer requested and the consumer has consented. That is stricter than the consent-based approach used elsewhere.
Applies to: Controllers and processors subject to the Maryland Online Data Privacy Act that hold sensitive data, sell personal data, or run targeted advertising that could reach consumers under 18.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanEvery other state privacy law treats sensitive data as something you may handle with consent. Maryland treats selling it as something you may not do at all.
The flat prohibition
Md. Code, Com. Law section 14-4607(a) sets out a list of things a controller or processor may not do. One of them is simply: sell sensitive data.
There is no qualifier. No consent exception, no necessity test, no carve-out for a consumer who actively asks for it. Compare that with New Jersey, which requires consent before processing sensitive data, or Texas, which gates it the same way. In those states a consent flow is a compliance answer. In Maryland, for sale specifically, there is no flow that makes it lawful.
For any business whose model includes monetizing data that touches health, sexual orientation, immigration status, precise location, or biometrics, this is the provision to check first.
Collection is gated by "strictly necessary", not "reasonably necessary"
The same subsection prohibits a controller or processor from collecting, processing, or sharing sensitive data concerning a consumer, except where the collection or processing is strictly necessary to provide or maintain a specific product or service requested by the consumer to whom the personal data pertains, and unless the controller obtains the consumer's consent.
Two conditions, and both must hold. Strict necessity tied to what the consumer actually asked for, and consent on top.
Note how that differs from Maryland's general data minimization rule in the following subsection, which uses reasonably necessary and proportionate. Sensitive data gets the tighter standard. A business that has calibrated its whole program to "reasonably necessary" will be under-compliant on the sensitive subset.
Minors are protected to 18, not 17
Section 14-4607(a) also prohibits processing the personal data of a consumer for the purposes of targeted advertising where the controller knew or should have known that the consumer is at least 13 years old and under the age of 18, and prohibits selling the personal data of such a consumer without consent.
Under 18 is a wider band than New Jersey's under 17, and the "should have known" standard means an age-blind product does not escape by never asking. If your service plausibly reaches teenagers, the safer position is to assume the rule applies.
The discrimination provisions
Two further prohibitions in the same subsection are easy to overlook because they read like general law rather than privacy law.
A controller or processor may not process personal data in violation of state or federal laws that prohibit unlawful discrimination against consumers. And it may not collect, process, or transfer personal data or publicly available data in a manner that unlawfully discriminates in, or otherwise unlawfully makes unavailable, the equal enjoyment of goods or services on the basis of race, color, religion, national origin, sex, sexual orientation, gender identity, or disability.
The subsection carves out self-testing to prevent or mitigate unlawful discrimination, diversifying an applicant, participant, or customer pool, and private clubs not open to the public as described in the Civil Rights Act of 1964.
Read together with the targeted advertising rules, these provisions put audience-selection logic squarely inside Maryland's privacy statute.
Purpose limitation
The final prohibition in the subsection is a purpose-compatibility rule: unless the controller obtains the consumer's consent, it may not process personal data for a purpose that is neither reasonably necessary to, nor compatible with, the disclosed purposes for which the personal data is processed, as disclosed to the consumer.
When this started applying
The Maryland Online Data Privacy Act of 2024 passed as House Bill 567 and was approved by the Governor on May 9, 2024 as Chapter 454. The General Assembly's record for the bill gives its effective date as October 1, 2025.
A note on citation
The chaptered text of Chapter 454 carries strike-and-insert amendment markup, so the item numbers inside section 14-4607(a) appear doubled where the bill renumbered them. This page therefore quotes the operative language and cites the subsection rather than pinning individual item numbers that cannot be read cleanly from the flattened document.
Next step
Maryland is the strictest US state on sensitive data, and a program built to the Virginia model will not meet it. The free 2-minute Obligation Scan tells you which US state privacy laws apply to your business and what each requires. See the Maryland MODPA overview for applicability, Maryland data minimization for the collection standard that applies to ordinary personal data, and New Jersey sensitive data consent for the consent-based contrast.
Compliance checklist
- Confirm no data flow sells sensitive data in Maryland, since no consent mechanism cures this and the prohibition is absolute.
- Apply the strictly-necessary test before collecting sensitive data: it must be strictly necessary to provide or maintain the specific product or service the consumer requested, and you must also obtain consent.
- Note that the sensitive-data standard is stricter than the general minimization standard in the same section, which uses reasonably necessary and proportionate.
- Stop targeted advertising to consumers you knew or should have known are at least 13 and under 18, and do not sell their personal data without consent.
- Treat 'should have known' as an active duty, because choosing not to determine age is not a defense.
- Check for non-discrimination exposure separately: the same subsection bars processing personal data in violation of state or federal anti-discrimination laws, and bars collecting, processing or transferring data in a manner that unlawfully discriminates in the equal enjoyment of goods or services.
Sources
- Chapter 454 (House Bill 567), Maryland Online Data Privacy Act of 2024, 2024 Laws of Maryland, Maryland General Assembly
- HB0567 legislation details, 2024 Regular Session (status, chapter, effective date), Maryland General Assembly
Last verified: 2026-08-23
Informational, not legal advice.