MODPA Readiness · Maryland Online Data Privacy Act

Be ready before Maryland's privacy cure period ends.

The Maryland Online Data Privacy Act is in force and the Attorney General is enforcing it. Until April 1, 2027, an organization that gets a notice of violation can still fix the problem before action is taken. We build the operational program that gets you there — alongside your counsel, who makes the legal calls.

April 1, 2027is when the MODPA cure period ends
Why now

Three dates that set the timeline.

October 1, 2025

The law took effect

MODPA became Maryland law, with data minimization limits that are stricter than most other states' privacy laws.

April 1, 2026

Enforcement began

The Attorney General's Consumer Protection Division began enforcing the law. Penalties can reach $10,000 per violation and $25,000 for repeat violations.

April 1, 2027

The cure period ends

After this date, the Attorney General no longer has to offer an opportunity to cure before acting. Readiness work done before then still gets the benefit of the cure period.

MODPA reaches further than many organizations expect: the consumer threshold is 35,000, not 100,000, and most nonprofits are covered. Healthcare administration, credit unions and regional financial services, retailers and e-commerce sellers, schools and colleges, associations, and marketing firms are among the organizations most likely to be affected. Whether it applies to you is a question for your counsel.

A quick self-check

Can your organization answer these today?

These are operational questions, not legal ones. If you can't answer most of them with a document, that's the gap a readiness program closes.

  1. Do you have a current inventory of the personal data you collect about Maryland residents, where it lives, and why you keep it?
  2. Do you know which vendors and service providers receive that data, and what they do with it?
  3. If a consumer asks to access, correct, delete, or move their data, who receives the request, and how do you track the response deadline?
  4. Does your website honor opt-out requests, including browser-based universal opt-out signals, and has anyone tested it?
  5. Do you collect any sensitive data (health, precise location, biometrics, children's data), and can you show it is strictly necessary?
  6. Do you use data for targeted advertising, profiling, or AI-driven decisions, and is that activity documented and assessed?
  7. Have the staff who handle personal data been trained, and can you prove it?
  8. Is someone accountable for the program, with a regular review cycle and a way to flag new uses of data?
Who does what

We build the program. Your counsel makes the legal calls.

Every engagement letter states this division, so there is never a question about what you are relying on.

Ulyx Advisory delivers

  • Data inventory and records of processing
  • Vendor and processor register, including data flows to third parties
  • Readiness documentation against your counsel's obligation checklist
  • Consumer-rights intake and fulfillment procedures, with response-clock tracking
  • Opt-out and universal opt-out specifications, and testing
  • Facilitated data protection assessments for activities counsel identifies
  • Security-safeguard documentation, staff training, and training records
  • Program governance and a sequenced, owner-assigned remediation roadmap

Your counsel decides

  • Whether MODPA applies, and whether any exemption does
  • Which processing is high-risk and needs an assessment
  • Privacy notice content
  • Vendor and data processing contract terms
  • Legal sufficiency of completed assessments
  • Any legal opinion, and all communication with the Attorney General

Counsel: see how we work with privacy counsel →

Packages & pricing

Clear starting prices. A fixed quote before we start.

The prices below are starting prices for small and mid-size organizations. After a 30-minute discovery call, you get a written scope and a fixed fee, so you know exactly what you will pay before any work begins. Every package excludes legal work, which stays with your counsel.

Start here

Readiness Snapshot

From$4,500 · about 2 weeks

For organizations that don't yet know where they stand.

  • Intake questionnaire and two working sessions
  • Data inventory workbook and vendor register
  • Readiness report on operational gaps
  • Prioritized remediation roadmap
  • A list of questions routed to your counsel

Starting price assumes up to about 250 employees, one business unit, up to 10 systems that hold personal data, and up to 5 staff interviews. The Snapshot fee is credited toward the Readiness Program if you start it within 60 days.

Ongoing

Fractional Privacy Program Lead

From$3,500 / month · 6-month minimum

For organizations without an internal privacy owner.

  • Monthly program review and metrics
  • Review of new data uses and new vendors
  • Oversight of consumer-rights requests
  • Assessment updates and quarterly training
  • A standing escalation path to your counsel

Starting price covers about 18 hours of program work a month for a single business unit.

Larger or multi-unit organizations

  • If you have more than about 250 employees, several business units, or more than 10 systems holding personal data, we give you a fixed quote after the discovery call.
  • Scope and price are set in writing in the engagement letter before work starts.
  • Anything outside the agreed scope is quoted and approved in writing before we do it. No surprise invoices.

Founding-client terms: our first MODPA clients receive reduced pricing in exchange for a reference and permission to describe the engagement. Ask about it on the discovery call.

Questions

Frequently asked

Does MODPA apply to my organization?

That is a legal determination, and your counsel makes it. What we can say generally: MODPA's thresholds are lower than most state privacy laws. It reaches organizations doing business in Maryland or targeting Maryland residents that, in the prior calendar year, processed personal data of at least 35,000 consumers (excluding data processed only to complete a payment), or at least 10,000 consumers while earning 20% or more of gross revenue from selling personal data. Unlike most states, it also covers most nonprofits. If you are unsure, a Readiness Snapshot starts by assembling the facts your counsel needs to decide.

What changes when the cure period ends on April 1, 2027?

Until April 1, 2027, the Maryland Attorney General may give an organization notice of a violation and an opportunity to cure it before taking action. After that date, the opportunity to cure is no longer required. Work done before the deadline still gets the benefit of the cure period.

How do you price larger organizations?

The prices on this page are starting prices for organizations of up to about 250 employees, with one business unit and up to 10 systems that hold personal data. Larger or multi-unit organizations receive a fixed quote after a 30-minute discovery call. Either way, the scope and price are set in writing before work starts, and any additional work is agreed in writing before it begins.

Is this legal advice?

No. Ulyx Advisory provides operational, non-legal consulting. We build the inventories, workflows, documentation, and training that a privacy program runs on. Your counsel makes every legal determination: whether the law applies, which processing needs a data protection assessment, what your notices say, and whether your contracts and assessments are legally sufficient.

We don't have privacy counsel. Can you still help?

Yes. We can start the operational work and help you identify independent Maryland privacy counsel for the legal determinations. You engage and pay counsel directly; Ulyx does not share fees or receive referral payments.

Can you implement the technical changes, like the opt-out mechanism?

We write the specification and test the result. Your IT team, web developer, or platform vendor makes the system changes, so you are not paying a consultant to do engineering work.

How does this connect to AI governance?

MODPA requires data protection assessments for profiling and other higher-risk processing, and AI tools are now a common source of both. Our AI governance work produces the AI system inventory and risk documentation that those assessments draw on, so the two can be done together.

This page is general information about the Maryland Online Data Privacy Act (Md. Code, Com. Law § 14-4701 et seq.), not legal advice, and it is not a substitute for the advice of counsel about your organization. Ulyx Advisory is not a law firm and does not provide legal advice or representation.

Find out where you stand.

A 30-minute discovery call is enough to tell whether a Snapshot or the full Program fits, what your fixed price would be, and how much time you have to work with.

Schedule a MODPA Discovery Call