Maryland Online Data Privacy Act of 2024
Enforcement and Remedies - Maryland MODPA

Maryland Online Data Privacy Act of 2024 MD-MODPA-Enforcement-Maryland-AG-Brown-CPD-Section-14-4613-10K-Per-Violation-Consumer-Protection-Act: Maryland MODPA Enforcement + Maryland AG + CPD + Section 14-4613 + USD 10K Per Violation + Consumer Protection Act

Manage Maryland Attorney General enforcement under Section 14-4613 and Maryland Consumer Protection Act (Md. Comm. Law Article Section 13-301). Maryland AG (Anthony Brown) Consumer Protection Division (CPD) EXCLUSIVE enforcement authority - NO private right of action. Violations of MODPA are unfair, abusive, or deceptive trade practices under Section 13-301(14)(xlii) (added by SB541). Penalties: civil penalties up to USD 10,000 per violation + USD 25,000 per repeat violation + restitution + injunctive relief + Consumer Protection Division investigations + AG subpoenas + AG court actions. 60-day cure period for first 24 months (until 1 October 2027) then NO CURE PERIOD permanent. AG may consider in determining penalty: number of violations + persistence of misconduct + length of time + willfulness + size + economic impact. Multistate Privacy AG Coalition coordination (Maryland + California + New York + Connecticut + Colorado + Texas + Oregon + Washington + Vermont + Delaware + Massachusetts + Michigan + New Hampshire + New Jersey + Pennsylvania + Rhode Island + Tennessee + 18-state network). Maryland AG Privacy Unit (within CPD) led by Assistant AG. Cooperation with FTC under FTC Act Section 5. Maryland Consumer Health Information Act + Maryland Personal Information Protection Act (PIPA) breach notification still apply concurrently. Maryland Biometric Information Privacy Act 2024 parallel enforcement.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 46 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29)
  • EHDSREG-4 Digital Health Authorities, Governance, MyHealth@EU
  • EHDSREG-5 Cross-Border Health Data Flows
  • CH-FADP-24 Cross-border transfer safeguards
  • CH-FADP-25 Compliance monitoring and auditing
  • FADP-10 Cross-Border Disclosure (Articles 16-18)

Bahrain PDPL · 2 controls

Malaysia PDPA 2010 · 2 controls

  • AUPRV-3 APP 6-9 Use/Disclosure, Direct Marketing, Cross-Border, Government Identifiers
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement

South Korea PIPA · 2 controls

  • APP-8 APP 8 - Cross-border disclosure of personal information
  • BB-DPA-17 Section 24 - Appropriate Safeguards

FedRAMP High · 1 control

  • AC-2 Account Management

FedRAMP Moderate · 1 control

  • AC-2 Account Management

GDPR · 1 control

  • GDPR-Art.45 Transfers on the basis of an adequacy decision
  • ICP-25 Supervisory Cooperation and Coordination
  • AC-2 Account Management
  • AC-2 Account Management
  • AC-2 Account Management
  • NISTSP34-1 Contingency Planning Policy, Programme, and Plan Coordination
  • DSOMM-6 Metrics, Maturity Measurement, and Continuous Improvement
  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • RUSPD-4 Special Categories, Biometric Data

South Korea ISMS-P · 1 control

Turkey KVKK · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 46 it maps to, and the evidence behind each claim, over MCP and REST.