Privacy
Maryland Online Data Privacy Act of 2024
The law applies to persons that conduct business in Maryland or provide products or services targeted to Maryland residents and that, during the preceding calendar year, controlled or processed personal data of at least 35,000 consumers, not counting data processed solely to complete a payment transaction. It also applies to persons that controlled or processed personal data of at least 10,000 consumers and derived more than 20 percent of gross revenue from the sale of personal data. The Maryland Attorney General's guidance states that nonprofits are not exempt, while government entities and some other categories are.
What the website needs
- A covered controller must provide a reasonably accessible, clear, and meaningful privacy notice that lists the categories of personal data processed including sensitive data, the purpose of processing, how consumers can exercise rights, appeal, or revoke consent, the categories of third parties with enough detail to understand each one's type or business model, the categories of personal data shared with third parties, and an active email address or other online contact mechanism.
- A controller that sells personal data or processes it for targeted advertising or significant profiling must clearly and conspicuously disclose that processing and how to opt out, and the disclosure must be prominently displayed and state in plain language whether the consumer's information will be sold or shared with a third party.
- A controller may not sell sensitive data at all, and may collect, process, or share sensitive data only when strictly necessary to provide or maintain a specific product or service the consumer requested; sensitive data includes consumer health data, precise geolocation data, biometric and genetic data, and data about a known child.
- A controller must limit collection of personal data to what is reasonably necessary and proportionate to provide or maintain a specific product or service the consumer requested.


