top of page
C&C Office Solutions Logo
Search

ODPA Enforcement Is Here: Is Your Maryland Business Exposed to $25,000 MCPA Penalties?

Writer: C&C Office Solutions
C&C Office Solutions
2 days ago
4 min read
MODPA logo with lock icon over Maryland outline on blue background, reading Maryland Online Data Privacy Act

If you run a small or medium-sized business in Maryland—whether you operate in Anne Arundel County, Howard County, Baltimore City, or across the broader Baltimore metro area—data privacy is no longer just a concern for national tech corporations. The Maryland Online Data Privacy Act (MODPA) took effect on October 1, 2025, and full enforcement by the Maryland Attorney General's Office has been active since April 1, 2026. That means the grace period is over, and regulators are now reviewing live data practices, not just policies on paper.


For local business leaders, ignoring this reality carries serious financial consequences. Under the Maryland Consumer Protection Act (MCPA), non-compliance can trigger civil penalties of up to $10,000 for initial infractions and up to $25,000 for repeat violations. A discretionary 60-day cure period remains available to alleged violators only until April 1, 2027—after that, the Attorney General can pursue enforcement immediately, with no opportunity to fix the problem first.


Here is a clear breakdown of what MODPA requires, how it affects your day-to-day operations, and how your business can establish an audit-ready security posture.


Does MODPA Apply to Your Small or Medium Business?


A common misconception among local executives is that state privacy laws only target multi-state corporations. In reality, MODPA's thresholds bring many regional SMBs directly into scope.


The law applies to any business or organization that conducts business in Maryland or targets products and services to Maryland residents, provided that during the previous year it met either of these criteria:


  • Controlled or processed the personal data of at least 35,000 Maryland consumers: This includes customer databases, online portal accounts, email subscriber lists, or site visitor tracking (excluding data handled purely to complete payment transactions).

  • Controlled or processed the personal data of at least 10,000 Maryland consumers AND derived over 20% of gross revenue from selling data: If your business model involves monetizing customer information, the threshold drops significantly.


If your enterprise operates in regions like Millersville, Gambrills, Columbia, or Baltimore and touches customer records at these volumes, compliance is mandatory—and, as of now, it's already being enforced.


The Core Shift: From Opt-Out Fine Print to "Data Minimization"


In the past, many companies relied on broad website terms and long privacy policies to gather user information freely, putting the burden on the customer to opt out. MODPA changes this dynamic by establishing a strict data minimization rule.

Under MODPA, your business can no longer collect customer data "just in case" it might be useful later. Every piece of personal information collected must be reasonably necessary and proportionate to provide or maintain the specific product or service requested by the customer—and this standard applies even where a customer has consented to broader collection.


Tight Controls on Sensitive Data


MODPA applies even stricter rules to "sensitive data," which covers:


  • Biometric and genetic data

  • Consumer health data

  • Precise geolocation tracking (defined as location data accurate within 1,750 feet)

  • Information revealing race, religious beliefs, sexual orientation, national origin, or citizenship status

  • Personal data of children under 13


Under the statute, selling sensitive data is completely banned, regardless of whether a consumer gives consent—MODPA is the first state privacy law to impose an unconditional sale ban of this kind. Collecting or processing sensitive data requires affirmative opt-in consent and must meet a "strictly necessary" standard, a higher bar than the "reasonably necessary" test applied to ordinary personal data.


The Cost of Non-Compliance: Fines Up to $25,000


Violations of MODPA are classified as unfair, abusive, or deceptive trade practices enforced by the Maryland Attorney General's Consumer Protection Division under the MCPA.


The financial penalties are among the highest state-level privacy fines in the country:


  • Up to $10,000 for a first violation

  • Up to $25,000 for each repeat violation


With enforcement active since April 1, 2026, state regulators expect organizations to maintain clear records demonstrating that their data collection practices comply with the law—today, not at some point in the future.


How C&C Office Solutions Helps You Stay Compliant and Secure


Meeting MODPA requirements does not require halting your digital marketing or completely rebuilding your IT infrastructure. It simply requires implementing practical administrative and technical controls to manage risk.


As a veteran-owned, local office technology and Managed IT provider headquartered in Millersville, C&C Office Solutions works alongside business leaders throughout Anne Arundel County, Howard County, and Baltimore to simplify complex compliance standards.


Our Managed Network IT Services protect your business through targeted cybersecurity and governance measures:


  • Continuous Data Flow Mapping: We analyze your network, cloud storage, and connected endpoints to identify exactly where personal data enters, gets stored, and leaves your business.

  • Automated Retention Schedules: We configure system policies to purge customer data automatically once it is no longer required for service delivery, satisfying MODPA's data minimization rule.

  • Endpoint Detection and Response (EDR): We monitor workstation and server endpoints 24/7 to safeguard stored records from ransomware, unauthorized access, and data breaches.

  • Data Protection Impact Assessments (DPIAs): We help your management team complete and document required privacy evaluations for high-risk data practices.


Protect Your Maryland Business Today


With MODPA enforcement already underway, a proactive approach is the best way to safeguard your organization against costly MCPA penalties and maintain the trust of your customers.


C&C Office Solutions provides local, reliable IT support designed to keep your network secure, efficient, and compliant.


Schedule an Executive Compliance Review with our Millersville-based team by calling (410) 864-0904 or visiting C&C Office Solutions online today.



Blue business banner for C&C Office Solutions with Improve your business with us, contact button, and phone number (410) 864-0904




Disclaimer: This article is provided for general informational purposes only and does not constitute legal advice. Data privacy laws, including the Maryland Online Data Privacy Act (MODPA), are subject to change, and their application can vary based on your business's specific circumstances. C&C Office Solutions is an IT services provider, not a law firm, and this content should not be relied upon as a substitute for consultation with a qualified attorney regarding your organization's compliance obligations.




Sources:


MODPA effective/enforcement dates, cure period

Applicability thresholds (35,000 / 10,000 consumers, 20% revenue test)

Penalty amounts ($10,000 / $25,000, MCPA enforcement)

Data minimization standard ("reasonably necessary and proportionate," applies even with consent)

Sensitive data categories, "strictly necessary" standard, unconditional sale ban

Precise geolocation definition (1,750 feet)

 
 
 

Comments


bottom of page