Skip to content

Evidence request lists

Maryland Online Data Privacy Act of 2024

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Consumer Rights - Maryland MODPA

MD-MODPA-Consumer-Rights-Section-14-4603-Access-Correction-Deletion-Portability-Opt-Out-Appeal
Maryland MODPA Consumer Rights + Section 14-4603 + Access + Correction + Deletion + Portability + Opt-Out + Appeal

Provide statutory consumer rights under Section 14-4603: (a) right to confirm whether controller is processing consumer personal data + access; (b) right to correct inaccuracies; (c) right to delete personal data provided by or about consumer; (d) right to obtain a copy in a portable readily usable format where technically feasible; (e) right to opt out of (i) targeted advertising (ii) sale of personal data (iii) profiling in furtherance of decisions producing legal or similarly significant effects. Response within 45 days extendable once by additional 45 days with notice. Free of charge first request per consumer per 12-month period. Authentication of consumer identity with no creation of new account. Authorised agent permitted including via Global Privacy Control opt-out preference signal under Section 14-4604. Appeal process (Section 14-4603(D)) within reasonable time + notice of deni

Artefacts an auditor will ask for
  • Subject rights request register with 45-day SLA evidence (extendable once 45 days)
  • Free of charge first request per 12-month evidence
  • Identity authentication procedure (no new account creation)
  • Authorised agent processing including GPC
  • Appeal mechanism with denial reasoning + AG complaint referral
  • Refusal documentation for manifestly unfounded/excessive
Where this commonly fails
  • No 45-day SLA tracking
  • New account creation required for verification (Section 14-4603 breach)
  • Authorised agent processing not operationalised
  • Appeal mechanism missing or no AG referral path

Controller Duties and DPA - Maryland MODPA

MD-MODPA-Controller-Duties-Security-DPA-Section-14-4608-14-4609-Processor-Contract-Assessment
Maryland MODPA Controller Duties + Section 14-4608 + Section 14-4609 + Processor Contract + DPA

Operate Maryland MODPA controller duties including security + processor contracts + Data Protection Assessment (DPA). Controllers must establish reasonable administrative + technical + physical security practices appropriate to volume and nature of personal data + nature of processing + state-of-the-art. Processor Contracts (Section 14-4608) must include: clear instructions for processing + nature and purpose + type of data + duration + rights and obligations of both parties + processor must (a) ensure confidentiality obligations on persons processing; (b) at controller direction delete or return all personal data at end of provision unless retention required by law; (c) make available to controller all information necessary to demonstrate compliance + cooperate with assessments by controller; (d) engage subprocessors only after providing opportunity to controller to object + flow down s

Artefacts an auditor will ask for
  • Reasonable security practices documentation (admin + technical + physical)
  • Processor contracts with Section 14-4608 mandatory clauses (instructions + confidentiality + return/delete + cooperate + subprocessor + technical measures)
  • Subprocessor authorisation register + flow-down evidence
  • DPA register under Section 14-4609 for (a) targeted ad (b) sale (c) profiling (d) sensitive (e) AI/ML training (f) heightened-risk
  • AG availability of DPAs upon request preparedness
  • Comparable processing activity grouping evidence
Where this commonly fails
  • Processor contracts pre-MODPA not refreshed with Section 14-4608 clauses
  • DPA missing for AI/ML training processing (new MODPA-specific trigger)
  • No subprocessor flow-down audit
  • DPA not retrievable for AG within reasonable time

Data Minimization Sensitive and Health Data - Maryland MODPA

MD-MODPA-Sensitive-Data-Health-Biometric-Section-14-4607-Reasonably-Necessary-Proportionate-Data-Minimization
Maryland MODPA Data Minimization + Sensitive + Health + Biometric + Section 14-4607 + Reasonably Necessary + Proportionate

STRONGEST US STATE DATA MINIMIZATION STANDARD: Section 14-4607 limits controller collection of personal data to what is REASONABLY NECESSARY AND PROPORTIONATE to provide or maintain the specific product or service requested by the consumer (unique dual reasonably-necessary-AND-proportionate test going beyond all other US state laws using only reasonably-necessary). Processing for any purpose other than provision of product/service requires explicit consumer consent. Sensitive Data (Section 14-4601(W)) requires affirmative opt-in consent - covers racial/ethnic origin + religious beliefs + consumer health data + sex life/sexual orientation + status as transgender or nonbinary + national origin + citizenship or immigration status + genetic data + biometric data + precise geolocation (1750-foot radius) + personal data of known child. Consumer Health Data (Section 14-4601(I)) separate categor

Artefacts an auditor will ask for
  • Section 14-4607 reasonably necessary AND proportionate analysis per processing purpose
  • Sensitive data inventory under Section 14-4601(W) with affirmative opt-in records
  • Consumer health data inventory under Section 14-4601(I)
  • 13-17 minor processing identification + opt-in records + targeted ad/sale ban evidence
  • Biometric data explicit consent records + no-collection-without-consent enforcement
  • Sale ban evidence for (a) consumer health data (b) sensitive data of 13-17 minors (c) biometric data
  • Precise geolocation 1750-foot radius compliance
Where this commonly fails
  • Reasonably-necessary-only test used (Maryland requires AND proportionate)
  • Sensitive opt-in implied not affirmative
  • Biometric collection without explicit consent (complete ban)
  • 13-17 minor identification relies on age gates not willful-disregard standard

Enforcement and Remedies - Maryland MODPA

MD-MODPA-Enforcement-Maryland-AG-Brown-CPD-Section-14-4613-10K-Per-Violation-Consumer-Protection-Act
Maryland MODPA Enforcement + Maryland AG + CPD + Section 14-4613 + USD 10K Per Violation + Consumer Protection Act

Manage Maryland Attorney General enforcement under Section 14-4613 and Maryland Consumer Protection Act (Md. Comm. Law Article Section 13-301). Maryland AG (Anthony Brown) Consumer Protection Division (CPD) EXCLUSIVE enforcement authority - NO private right of action. Violations of MODPA are unfair, abusive, or deceptive trade practices under Section 13-301(14)(xlii) (added by SB541). Penalties: civil penalties up to USD 10,000 per violation + USD 25,000 per repeat violation + restitution + injunctive relief + Consumer Protection Division investigations + AG subpoenas + AG court actions. 60-day cure period for first 24 months (until 1 October 2027) then NO CURE PERIOD permanent. AG may consider in determining penalty: number of violations + persistence of misconduct + length of time + willfulness + size + economic impact. Multistate Privacy AG Coalition coordination (Maryland + Californi

Artefacts an auditor will ask for
  • Maryland AG CPD correspondence and inquiry response evidence
  • Penalty exposure assessment (USD 10K per violation + USD 25K per repeat)
  • 60-day cure tracking (until 1 October 2027 sunset) + post-2027 no-cure preparedness
  • Multistate Privacy AG Coalition coordination records (18-state network)
  • FTC Act Section 5 cooperation evidence
  • Maryland Biometric Information Privacy Act + PIPA + Consumer Health Information Act parallel compliance evidence
  • Maryland AG Privacy Unit Assistant AG contact log
Where this commonly fails
  • No 60-day cure tracking process during sunset window
  • Post-1-October-2027 no-cure preparedness gap
  • Multistate AG inquiry handling lacks coordination
  • Maryland Biometric Privacy Act parallel exposure not flagged

Privacy Notice - Maryland MODPA

MD-MODPA-Notice-Section-14-4605-Categories-Purposes-Rights-Sale-Disclosure-Biometric-Health
Maryland MODPA Privacy Notice + Section 14-4605 + Categories + Purposes + Rights + Sale Disclosure + Biometric Health

Provide reasonably accessible clear and meaningful privacy notice under Section 14-4605 disclosing: (i) categories of personal data processed; (ii) purpose(s) of processing; (iii) how consumers may exercise rights under Section 14-4603 including appeal; (iv) categories of personal data shared with third parties; (v) categories of third parties with whom personal data shared; (vi) ACTIVE EMAIL ADDRESS or other online mechanism for consumer to contact controller; (vii) sale disclosure (whether controller sells personal data + opt-out mechanism); (viii) targeted advertising disclosure (whether controller engages + opt-out mechanism); (ix) biometric data and consumer health data specific disclosures including third-party categories; (x) processing of personal data of consumers between 13 and under 18 years disclosure; (xi) opt-out preference signal recognition (Global Privacy Control). Notic

Artefacts an auditor will ask for
  • MODPA-compliant privacy notice with Section 14-4605 11 mandatory elements
  • Active email or online contact mechanism evidence
  • Biometric and consumer health data specific disclosure section
  • 13-17 minor processing disclosure
  • Multilingual notice where consumer population requires
  • Material change notification audit log
Where this commonly fails
  • No active email or online mechanism for consumer contact
  • Biometric/health data specifics missing from notice
  • Sale and targeted advertising disclosure incomplete
  • GPC opt-out preference signal not described in notice

Pseudonymisation and De-Identification - Maryland MODPA

MD-MODPA-Pseudonymisation-De-Identification-Section-14-4610-4611-Internal-Research-Aggregated
Maryland MODPA Pseudonymisation + De-Identification + Section 14-4610 + 14-4611 + Internal Research + Aggregated

Apply pseudonymisation and de-identification under Sections 14-4610 and 14-4611 to enable lawful internal research + product improvement + aggregated reporting while protecting consumer privacy. Pseudonymised Data definition (Section 14-4601(V)) - personal data that cannot be attributed to specific consumer without use of additional information kept separately and subject to technical and organisational measures preventing re-identification. De-Identified Data definition - cannot reasonably be linked to consumer or household + technical safeguards + business processes preventing re-identification + publicly commit to maintain without re-identifying + contractually bind recipients. Aggregated Consumer Information - statistical de-identified about group/category from which individual identities removed + not linked to any consumer. Internal research exemption (Section 14-4611) permits proc

Artefacts an auditor will ask for
  • Pseudonymisation procedures with separation of identifier and additional information + technical/organisational measures preventing re-identification
  • De-identification per Section 14-4611 with public commitment + contractual binding of recipients
  • Aggregated Consumer Information procedures
  • Internal research exemption documentation (product improvement + bug repair + security + scientific research)
  • Research ethics review board records + data destruction timeline
  • Maryland Consumer Health Information Act cross-walk + HIPAA Safe Harbor/Expert Determination for health
Where this commonly fails
  • Pseudonymised data still linkable due to weak separation
  • De-identification public commitment missing
  • Internal research not bounded by destruction timeline
  • HIPAA Safe Harbor not cross-walked for consumer health data

Scope and Authority - Maryland MODPA

MD-MODPA-Scope-SB541-Title-14-Subtitle-46-Sections-14-4601-14-4614-Effective-1-October-2025-AG-Brown
Maryland MODPA Scope + SB541 + Title 14 Subtitle 46 + Sections 14-4601 to 14-4614 + Effective 1 October 2025 + AG Brown

Establish the legal foundation of Maryland Online Data Privacy Act of 2024 (Senate Bill 541) codified at Md. Comm. Law Article Title 14 Subtitle 46 Sections 14-4601 through 14-4614. Signed by Governor Wes Moore 9 May 2024 + effective 1 October 2025. Maryland Attorney General (currently Anthony Brown) Consumer Protection Division exclusive enforcement authority. Apply targeted thresholds (LOWER than most US state laws): entities controlling or processing personal data of (a) 35,000 or more Maryland consumers OR (b) 10,000 or more consumers AND deriving 20% or more gross revenue from sale of personal data. Carve-outs for GLBA-regulated financial institutions + HIPAA-covered entities and business associates + Maryland Insurance Article entities + air carriers (49 USC 41713) + non-profit organisations + research organisations under specific conditions + Maryland state and local government bo

Artefacts an auditor will ask for
  • MODPA threshold assessment (35K consumers OR 10K + 20% revenue from sale)
  • Carve-out analysis (GLBA + HIPAA + Maryland Insurance + air carriers + non-profit + research + state/local govt)
  • Maryland AG CPD correspondence records
  • Maryland Genetic Information Privacy Act 2020 + Biometric Information Privacy Act 2024 + PIPA cross-walk
  • 1 October 2025 effectiveness gap analysis
Where this commonly fails
  • Threshold not assessed against 35K/10K lower triggers
  • Carve-out claimed but unsupported documentation
  • 1 October 2025 readiness gap not assessed
  • GLBA/HIPAA partial-entity scope not delineated

Universal Opt-Out Mechanism - Maryland MODPA

MD-MODPA-Universal-Opt-Out-Section-14-4604-GPC-Global-Privacy-Control-Recognition-Mandatory
Maryland MODPA Universal Opt-Out + Section 14-4604 + Global Privacy Control + Mandatory Recognition

Recognise and honour Universal Opt-Out Mechanism under Section 14-4604 - controllers MUST allow consumers to opt out of targeted advertising and sale of personal data through user-selected universal opt-out mechanism (Global Privacy Control GPC or equivalent). Mechanism must be (a) unaffiliated with the controller; (b) easy for reasonable consumer to use; (c) clearly described to consumer; (d) does not unfairly disadvantage another controller; (e) does not make use of a default that opt-out signal is set or unset which the consumer did not affirmatively select. Controller may not require consumer to actively select opt-out from a default that does not opt out. Effective from 1 October 2025 with no cure period for GPC failure to honour after first 24 months. Coordination with multistate GPC recognition by Colorado + Connecticut + Texas + California (CPRA via CCPA Regulation 7025) + Delawa

Artefacts an auditor will ask for
  • GPC opt-out preference signal detection implementation evidence
  • Signal-detection audit log + consumer confirmation records
  • Browser fingerprinting and inference-based tracking opt-out evidence
  • Multistate GPC recognition cross-walk (CO + CT + TX + CA + DE + MT + NE + NH + NJ + OR coordination)
  • Mechanism unaffiliated + easy + clearly described + no default + no controller fairness disadvantage evidence
Where this commonly fails
  • GPC not honoured (1 October 2025 effective + no cure post 2027 - major penalty exposure)
  • Default opt-out set without affirmative selection (Section 14-4604 breach)
  • Browser fingerprinting still tracking opt-out consumers
  • Multistate GPC recognition inconsistent
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Maryland Online Data Privacy Act of 2024 framework page.