Maryland's Privacy Law Is Now Enforced: An Ad Stack Checklist for Publishers
Maryland began enforcing its Online Data Privacy Act on April 1. Its minimization rules and bans on selling sensitive and minors' data reach deep into ad stacks, especially for health sites.
As of April 1, 2026, the Maryland Online Data Privacy Act (MODPA) governs personal data processing in the state, and the Maryland Attorney General can enforce it. The law formally took effect on October 1, 2025, but it does not apply to processing before April 1 of this year. For publishers used to the Virginia-style template that most states have copied, Maryland is different in ways that matter for advertising. This is not legal advice. It is a map of where the law touches the ad stack, so you know what to raise with counsel.
Who is covered
MODPA applies to businesses that process the personal data of at least 35,000 Maryland consumers in a year, or at least 10,000 consumers if the business earns more than 20 percent of its gross revenue from selling personal data. Those thresholds are low. A mid-sized national publisher with ordinary Maryland readership can pass 35,000 consumers without trying.
Where Maryland departs from the usual template
Minimization tied to what the consumer asked for
Most state laws let a business collect what is necessary for the purposes it has disclosed. Maryland ties collection to what is reasonably necessary and proportionate to provide or maintain the specific product or service the consumer requested. For sensitive data the bar is higher: collection and processing must be strictly necessary for that product or service. A reader asked for an article. Whether advertising-related data collection is necessary to deliver that article is a question lawyers will argue about for years, which is exactly why publishers should document their reasoning now.
No sale of sensitive data, even with consent
As Kelley Drye's analysis notes, Maryland prohibits the sale of sensitive data outright, and consent does not override the ban. Sensitive data includes categories such as health information. Most other state laws allow the sale of sensitive data with opt-in consent. Maryland does not.
Minors under 18
Maryland bars selling the personal data of consumers under 18, and using it for targeted advertising, where the business knew or should have known the consumer was a minor. That knowledge standard is broader than actual knowledge. A site with an obvious teen audience cannot rely on the absence of an age field.
Assessments and the cure period
Targeted advertising, data sales and sensitive data processing all call for data protection assessments, and Maryland's assessments must address each algorithm used, which is broader than comparable laws. A 60-day cure period is available through April 1, 2027, which gives some room, but enforcement is live now.
Why health publishers should look first
Health and wellness sites carry the most exposure because the content itself can imply sensitive data. A page about a specific condition, loaded by an identifiable browser, can generate a data point that a bidder or data partner treats as a health-related interest. If any part of your stack passes page-level content signals together with a user identifier to a third party that pays for it, you need to know whether that flow could be characterized as a sale of sensitive data. Maryland does not offer the consent escape hatch that other states do.
The same logic applies, less acutely, to finance topics such as debt and credit, parenting content and some lifestyle categories.
An ad stack checklist
- Map what leaves the page. For every partner in your wrapper, ad server and tag manager, list what it receives: identifiers, IP address, page URL, content categories, first-party segments. Most teams cannot produce this list quickly, and it is the foundation for everything else.
- Separate contextual from personal. Signals about the page, sent without a user identifier, are much easier to defend than the same signals tied to a person. Where you can, send content categories without user IDs on sensitive templates.
- Review sensitive-content templates. For condition pages and similar content, consider disabling user ID modules and first-party audience segments and relying on contextual demand. Test the revenue impact on a slice of traffic before rolling it out.
- Check your opt-out plumbing. Confirm that opt-outs, including browser signals such as Global Privacy Control where you honor them, actually reach your bidders. In Prebid that means your consent module is passing the GPP string and your adapters respect it. Test it in a browser with the signal enabled and inspect the bid requests.
- Look at age signals. If you publish content aimed at teens, such as gaming guides or study resources, decide how those sections will be treated under a knew-or-should-have-known standard.
- Update contracts. Data processing terms with SSPs and data partners should reflect Maryland's restrictions, especially on onward use of sensitive data.
- Write the assessment. Document why each processing activity is necessary, what risks it carries and what safeguards you use. Writing it will surface flows nobody can justify.
Revenue impact, honestly
Removing identifiers from sensitive templates will cost something. How much depends on your demand mix: sites with strong contextual and direct-sold demand will feel it less than sites that depend on audience-targeted open auction spend. The practical approach is to measure it on a subset of traffic and decide with real numbers rather than guessing in either direction.
Maryland will not be the last state to move in this direction. A stack where identity is an add-on to strong contextual signals, rather than the foundation, is a hedge that pays off with every new law.
The takeaway
Maryland raised the bar from “disclose and allow opt-out” to “collect only what is necessary,” with no consent workaround for sensitive data. Publishers who can show what data leaves their pages, and why, are in a far better position than those who find out during an inquiry. If your ad setup is managed, ask your partner for the data-flow map. If they cannot produce one, that is your first finding.
Related Articles
July's Privacy Law Changes: A Checklist for Health and Finance Publishers
Connecticut, Arkansas and Virginia changes took effect July 1, and IAB Tech Lab just proposed GPP updates. What health, finance and other sensitive-content publishers should check.
Privacy Sandbox Is Winding Down in Chrome. Time to Clean Up Your Wrapper
Chrome 150 is now rejecting Protected Audience calls as Google retires most Privacy Sandbox APIs. Here is what to remove from your ad stack and what stays the same.
July 1 Privacy Deadlines: Connecticut and Arkansas Tighten Teen Ad Rules
On July 1, Connecticut's amended privacy law and Arkansas's children's and teens' privacy law take effect, both restricting targeted ads to minors. What publishers should change first.