The Maryland Online Data Privacy Act is in force and the Attorney General is enforcing it. Until April 1, 2027, an organization that gets a notice of violation can still fix the problem before action is taken. We build the operational program that gets you there — alongside your counsel, who makes the legal calls.
MODPA became Maryland law, with data minimization limits that are stricter than most other states' privacy laws.
The Attorney General's Consumer Protection Division began enforcing the law. Penalties can reach $10,000 per violation and $25,000 for repeat violations.
After this date, the Attorney General no longer has to offer an opportunity to cure before acting. Readiness work done before then still gets the benefit of the cure period.
MODPA reaches further than many organizations expect: the consumer threshold is 35,000, not 100,000, and most nonprofits are covered. Healthcare administration, credit unions and regional financial services, retailers and e-commerce sellers, schools and colleges, associations, and marketing firms are among the organizations most likely to be affected. Whether it applies to you is a question for your counsel.
These are operational questions, not legal ones. If you can't answer most of them with a document, that's the gap a readiness program closes.
Every engagement letter states this division, so there is never a question about what you are relying on.
Counsel: see how we work with privacy counsel →
The prices below are starting prices for small and mid-size organizations. After a 30-minute discovery call, you get a written scope and a fixed fee, so you know exactly what you will pay before any work begins. Every package excludes legal work, which stays with your counsel.
For organizations that don't yet know where they stand.
Starting price assumes up to about 250 employees, one business unit, up to 10 systems that hold personal data, and up to 5 staff interviews. The Snapshot fee is credited toward the Readiness Program if you start it within 60 days.
Everything in the Snapshot, plus the build-out.
Starting price assumes the same footprint as the Snapshot: up to about 250 employees, one business unit and up to 10 systems that hold personal data.
For organizations without an internal privacy owner.
Starting price covers about 18 hours of program work a month for a single business unit.
Founding-client terms: our first MODPA clients receive reduced pricing in exchange for a reference and permission to describe the engagement. Ask about it on the discovery call.
That is a legal determination, and your counsel makes it. What we can say generally: MODPA's thresholds are lower than most state privacy laws. It reaches organizations doing business in Maryland or targeting Maryland residents that, in the prior calendar year, processed personal data of at least 35,000 consumers (excluding data processed only to complete a payment), or at least 10,000 consumers while earning 20% or more of gross revenue from selling personal data. Unlike most states, it also covers most nonprofits. If you are unsure, a Readiness Snapshot starts by assembling the facts your counsel needs to decide.
Until April 1, 2027, the Maryland Attorney General may give an organization notice of a violation and an opportunity to cure it before taking action. After that date, the opportunity to cure is no longer required. Work done before the deadline still gets the benefit of the cure period.
The prices on this page are starting prices for organizations of up to about 250 employees, with one business unit and up to 10 systems that hold personal data. Larger or multi-unit organizations receive a fixed quote after a 30-minute discovery call. Either way, the scope and price are set in writing before work starts, and any additional work is agreed in writing before it begins.
No. Ulyx Advisory provides operational, non-legal consulting. We build the inventories, workflows, documentation, and training that a privacy program runs on. Your counsel makes every legal determination: whether the law applies, which processing needs a data protection assessment, what your notices say, and whether your contracts and assessments are legally sufficient.
Yes. We can start the operational work and help you identify independent Maryland privacy counsel for the legal determinations. You engage and pay counsel directly; Ulyx does not share fees or receive referral payments.
We write the specification and test the result. Your IT team, web developer, or platform vendor makes the system changes, so you are not paying a consultant to do engineering work.
MODPA requires data protection assessments for profiling and other higher-risk processing, and AI tools are now a common source of both. Our AI governance work produces the AI system inventory and risk documentation that those assessments draw on, so the two can be done together.
This page is general information about the Maryland Online Data Privacy Act (Md. Code, Com. Law § 14-4701 et seq.), not legal advice, and it is not a substitute for the advice of counsel about your organization. Ulyx Advisory is not a law firm and does not provide legal advice or representation.
A 30-minute discovery call is enough to tell whether a Snapshot or the full Program fits, what your fixed price would be, and how much time you have to work with.
Schedule a MODPA Discovery Call