Maryland Online Data Privacy Act of 2024 (Md. Code, Com. Law 14-4601 et seq.; 2024 Md. Laws ch. 455, SB 541)
Below is what the official text of Maryland Online Data Privacy Act of 2024 (Md. Code, Com. Law 14-4601 et seq.; 2024 Md. Laws ch. 455, SB 541) states about whom it covers, when it applies to a business and since when. Where the pages we read do not say, the row says "not stated".
The wording shown is taken from the official page named in each row. The duties of a business and the contents of a privacy notice are in the paid checklist.
Typical situations, run through the same conditions as the check
- A for-profit US business with 150,000 people in Maryland and $30 million revenue: Applies, or may apply: conditions to check.
- The same business with 8,000 people in Maryland: Not triggered by these answers.
- A US business with no users in Maryland: Not triggered by these answers.
Judged on 2026-10-06. Our law data was last verified on 2026-10-06; a law that took effect after that date is not in it. These situations leave other answers blank or neutral: use the check for your own.
What the official text states
| Question | What the official text states | Source |
|---|---|---|
| What it covers | Regulates the manner in which a controller or processor in possession of a consumer's personal data may process it, and authorizes consumers to exercise rights over that data.Official wordingFOR the purpose of regulating the manner in which a controller or a processor in possession of a consumer’s personal data may process the consumer’s personal data; authorizing a consumer to exercise certain rights | mgaleg.maryland.gov read 2026-10-06 |
| When it applies to a business | Applies (14-4602) to a person that conducts business in Maryland or provides products or services targeted to Maryland residents and that, during the preceding calendar year, controlled or processed the personal data of at least 35,000 consumers (excluding data processed solely to complete a payment transaction), or at least 10,000 consumers while deriving more than 20% of gross revenue from the sale of personal data. Conditions to check: Business must conduct business in Maryland or provide products or services targeted to Maryland residents. The 35,000 count excludes data processed solely to complete a payment transaction. Thresholds look at the preceding calendar year. 14-4603 exempts state and local government bodies, registered national securities associations, financial institutions and their affiliates or GLBA-subject data, and a narrow class of nonprofit controllers (those assisting law enforcement on insurance fraud or first responders in catastrophes); other nonprofits are not exempt. Data exemptions include HIPAA protected health information and others. The text we read is a chapter law that shows amendments as struck and inserted text with the striking lost, so the wording of 14-4602 contains leftover words from deleted text. Official wording35,000 CONSUMERS, EXCLUDING PERSONAL DATA CONTROLLED OR PROCESSED SOLELY FOR THE PURPOSE OF COMPLETING A PAYMENT TRANSACTION; OR 2. (II) (2) CONTROLLED OR PROCESSED THE PERSONAL DATA OF AT LEAST 10,000 CONSUMERS AND DERIVED MORE THAN 20% OF ITS GROSS REVENUE FROM THE SALE OF PERSONAL DATA. | mgaleg.maryland.gov read 2026-10-06 |
| In force from | Not stated on the official pages we read. The text we read shows the date only through struck and inserted words, so we do not state it. | — |
| Privacy notice | Included in the paid checklist. See the checklist | — |
| Consent and opt-out | Included in the paid checklist. See the checklist | — |
| Rights of individuals | Included in the paid checklist. See the checklist | — |
| Data protection officer | Not stated on the official pages we read. the text we read contains no provision requiring a data protection or privacy officer | — |
| Breach notification | Not stated on the official pages we read. separate breach-notification statute not read | — |
| What the privacy notice must contain | Included in the paid checklist. See the checklist | — |
What we do not cover
These areas are outside this site, so nothing on this page says anything about them:
- Privacy laws for particular sectors (for example health care, banking and credit, education)
- Rules specific to children's online privacy
- Cookie and electronic-communications rules (including consent for cookies and marketing messages)
- Employee, job applicant and contractor data
- Rules on sending personal data to other countries
- US state data-breach notification laws (a separate set of state laws)
- US state privacy laws that are not yet in force, and state laws on particular topics (for example biometric or health data)
- Privacy laws of countries that are not listed here
- Planned changes to the laws listed here