Pandectes GDPR Compliance - 3,000+ Verified ⭐⭐⭐⭐⭐ 5/5 Reviews Worldwide - #1 on Shopify 🏅

Maryland Online Data Privacy Act (MODPA) Compliance

Pandectes GDPR Compliance helps Shopify stores meet MODPA requirements by managing cookie consent, honoring opt-out signals and handling consumer privacy requests.

Start Free
MODPA Maryland

The #1 cookie consent app for Shopify, trusted by 185k stores

  • Nike Strength
  • Reebok
  • Ted Baker
  • Juicy Couture
  • Aje
  • Casely
  • Oracle Red Bull Racing
  • KFC
  • Flying Tiger Copenhagen
  • Sennheiser
  • Susanne Kaufmann
  • Aldo
  • Victoria Beckham
  • Scalpers
  • UGREEN

What is MODPA?

The Maryland Online Data Privacy Act (MODPA) is Maryland’s comprehensive consumer privacy law. It gives Maryland residents rights over their personal data and sets rules for the businesses that collect and use it. MODPA follows the general model of other US state privacy laws, but it is widely seen as one of the strictest, mainly because of its data minimization rules and its limits on sensitive data.

Under MODPA, Maryland residents have the right to:

  • Confirm whether a business processes their personal data, and access that data
  • Correct inaccurate personal data
  • Delete personal data
  • Obtain a portable copy of their personal data
  • Obtain a list of the categories of third parties to which their data has been disclosed
  • Opt out of targeted advertising, the sale of their personal data, and certain types of profiling

The law also sets stricter rules than most states in several areas. A business must limit the personal data it collects to what is reasonably necessary and proportionate to provide the product or service the consumer asked for. Sensitive data, such as health data, precise geolocation, biometric data, or data revealing racial or ethnic origin, may only be collected or processed when it is strictly necessary for the requested product or service, and selling sensitive data is prohibited outright. Businesses may not sell personal data or use it for targeted advertising when they know, or should have known, that the consumer is under 18.

Who does the MODPA apply to?

MODPA applies to businesses that operate in Maryland or offer products or services targeted to Maryland residents, and that in the previous calendar year controlled or processed the personal data of at least 35,000 Maryland consumers (not counting data used only to complete a payment), or of at least 10,000 Maryland consumers while earning more than 20% of gross revenue from selling personal data. Some entities and data types are exempt, such as government bodies and data covered by the federal Gramm-Leach-Bliley Act.

What happens if I don’t comply with the MODPA?

A violation of MODPA is treated as an unfair, abusive, or deceptive trade practice under the Maryland Consumer Protection Act. Key points about enforcement:

  • The Maryland Attorney General, through its Consumer Protection Division, enforces the law.
  • Civil penalties under the Consumer Protection Act can reach $10,000 per violation, and up to $25,000 for each repeated violation.
  • MODPA does not give consumers a private right of action to sue under the law itself.
  • For violations that occur on or before April 1, 2027, the Attorney General may send a notice of violation and allow at least 60 days to fix the problem, if it decides a cure is possible. This is discretionary, not guaranteed, and it ends after that date.

When did the MODPA go into effect?

MODPA took effect on October 1, 2025. Its obligations apply to personal data processing activities that take place on or after April 1, 2026, so stores selling to Maryland residents should already be in compliance.

Complying with the MODPA

If your online store sells to Maryland residents and meets the thresholds above, most of your practical work involves cookies and tracking. Marketing pixels, analytics tags, and advertising cookies often count as targeted advertising or a “sale” of personal data under state privacy laws, so they need to respect each visitor’s choices.

Practical steps for a Shopify store include:

  • Offer a clear opt-out. Give visitors an easy way to opt out of targeted advertising and the sale of their personal data, such as a “Do not sell or share my personal information” link, and make sure tracking stops once they do.
  • Honor opt-out preference signals. MODPA recognizes opt-out preference signals sent by a browser or device, such as Global Privacy Control (GPC). Treating a GPC signal as a valid opt-out is the safest approach for Maryland visitors.
  • Collect less data. Review your apps, pixels, and forms, and remove anything that collects personal data you do not need to fulfill orders or provide the service your customers asked for.
  • Be careful with sensitive data. Do not sell sensitive data, and only collect it when it is strictly necessary. Avoid targeted advertising to visitors you know or should know are under 18.
  • Update your privacy notice. Explain what personal data you collect, why, which categories of third parties receive it, and how consumers can exercise their rights.
  • Handle consumer requests. Set up a reliable way for customers to request access, correction, deletion, or a copy of their data, and respond within the required timeframe.

A consent management platform makes these steps much easier to maintain. Pandectes GDPR Compliance is built for Shopify stores and provides a cookie banner with opt-out options for US states, a “Do not sell or share my personal information” link, and support for the Global Privacy Control signal. It automatically scans and classifies the cookies on your store, generates a cookie declaration, keeps consent logs, and helps you handle data subject requests. Region-specific banner settings use geolocation to show the right experience to visitors from Maryland and other states.

Privacy laws differ in their details and continue to change, so review your setup with legal counsel where appropriate.

Make your Shopify Store's use of cookies and online tracking compliant today

Try for free