Maryland data privacy and data broker removal

Maryland has a comprehensive privacy law that gives you the right to access, delete, and control your personal data. Here's how those rights work in practice, and how to get yourself off the data brokers that trade in it.

At a glance
Comprehensive privacy law? Yes — Maryland Online Data Privacy Act (MODPA)
In effect since October 1, 2025
Your core rights Access & Know, Correct, Delete, Data Portability +4 more
Honors Global Privacy Control? Yes
Data-broker registry? No
Can you sue? (private right of action) No
Enforced by Maryland Attorney General's Consumer Protection Division
Last verified June 2026 Reviewed quarterly

Your rights in Maryland

Maryland residents are protected by the Maryland Online Data Privacy Act (MODPA).

Sensitive data gets extra protection. Companies can only process your most sensitive personal information when it's strictly necessary to deliver something you asked for, and they can't sell it at all. That covers biometric data, precise location, health information, race and ethnicity, and sexual orientation.

Does this cover the company that has my data?

Probably. MODPA applies to any business that controls or processes the personal data of at least 35,000 Maryland residents (not counting data used only to complete a payment), or at least 10,000 residents if it earns more than 20% of its revenue from selling personal data. Its exemptions are narrow: there's no blanket carve-out for health-regulated entities and only a limited nonprofit exception, so it reaches more businesses than most state privacy laws.

What's changing.
  • MODPA took effect October 1, 2025. Enforcement covers data processing on or after April 1, 2026.
  • It carries the strictest data-minimization rules in the country, and it's the first US law to ban the sale of sensitive data outright.

How to remove yourself from data brokers in Maryland

Your state law gives you the right to request deletion. The hard part is exercising it everywhere your information shows up. Here are the most effective steps, in order.

1. Enable Global Privacy Control

Global Privacy Control is a free browser setting that automatically tells every website you visit not to sell or share your data. It takes about two minutes to turn on and then works in the background on every site. Maryland law requires covered businesses to honor it, so it carries legal weight, not just a polite request.

2. Submit direct opt-out requests

For companies that Global Privacy Control doesn't reach, you can file requests one at a time. Look for the "Do not sell my personal information" link in the website footer; most major brokers have one. You can also send formal access, deletion, or correction requests through each company's privacy policy page.

Under Maryland's law, covered companies have to respond within the statutory deadline. If they don't, you have grounds to file a complaint with the Maryland Attorney General's Consumer Protection Division.

3. Keep it removed

Here's the part nobody tells you: even after you finish every step above, brokers rebuild your profile from public records, data-sharing networks, and commercial databases. Within a few months, the listings come back. Staying off isn't a one-time task; it's ongoing work that's hard to keep up by hand.

Delist finds where your information is exposed, files the removals for you, then re-runs a full scan every month so it stays down. Start with a free scan to see what's out there.

Run a free scan

Maryland's data broker law: what it means for you

Maryland doesn't have a dedicated data-broker registry. Many national brokers register in California and will honor opt-out requests from residents of any state, but without a Maryland law requiring it, you have little recourse if a broker ignores you. We don't work from a fixed list of sites: our scan searches the open internet for wherever your information shows up, then handles the removals across states and brokers in one place.

Other privacy protections in Maryland

Beyond the comprehensive privacy law, Maryland has protections that may apply to you:

How to file a privacy complaint in Maryland

File with the Maryland Attorney General's Consumer Protection Division: marylandattorneygeneral.gov

State agencies mostly enforce privacy laws in the aggregate: they investigate patterns of violations rather than resolving individual disputes. Filing still matters, because it creates a record that helps trigger enforcement.

Frequently asked questions

Does Maryland have a data privacy law?
Yes. Maryland residents are protected by the Maryland Online Data Privacy Act (MODPA), which gives you rights to access, delete, and control your personal data.
Can I sue a company for violating my privacy in Maryland?
Generally no. Privacy enforcement in Maryland is handled by the Maryland Attorney General's Consumer Protection Division. You can't sue for most violations.
How do I opt out of data brokers in Maryland?
Enable Global Privacy Control, submit direct opt-out requests to each broker, and consider a removal service to automate the process. Maryland has no broker registry.
Does Maryland require websites to honor Global Privacy Control?
Yes. Maryland law requires covered businesses to treat Global Privacy Control as a valid opt-out request. Enable it in your browser for automatic protection.

Sources

This page is privacy-rights information, not legal advice. Privacy law changes frequently; verify current rules with your state privacy agency or a licensed attorney before acting. Last verified 2026-06-22. We re-check state privacy laws quarterly.

Take back your privacy in Maryland

Delist finds where your information is exposed, files the removals for you, and re-runs a full scan every month so it stays down.

Run a free scan