Feature Data Privacy
Maryland MODPA Is in Enforcement: The Sensitive Data Compliance Gap Fintechs Can't Cover With GLBA
Maryland's MODPA has been in enforcement since April 1, 2026 — and the GLBA entity-level exemption most fintechs assume protects them doesn't cover geolocation, biometrics, or marketing behavioral data. Here's where the gap is and what to do about it.
Table of Contents
TL;DR
- Maryland MODPA has been in enforcement since April 1, 2026 — the Maryland AG can now pursue civil penalties without waiting for a federal action
- The GLBA entity-level exemption protects core financial transaction data but leaves geolocation, biometric, and marketing behavioral data exposed to MODPA requirements
- MODPA is the first state privacy law to completely ban the sale of sensitive data — even with consumer consent — making it stricter than CPRA, Virginia, and Colorado
- Fintechs that sell behavioral analytics, use biometrics for identity verification, or collect geolocation for fraud detection may already be out of compliance
Your payment processing data is covered. Your fraud detection geolocation data probably isn’t. And if you’ve been selling behavioral or engagement analytics to any third party — with or without consumer consent — Maryland just made that illegal.
The Maryland Online Data Privacy Act (MODPA) took effect October 1, 2025. The state’s enforcement mechanism went live April 1, 2026. Three months into active enforcement, most fintech compliance teams are still operating under the assumption that GLBA covers everything they do in Maryland. For many, that assumption has a gap large enough to drive a consent order through.
What MODPA Actually Requires
MODPA is Maryland’s comprehensive consumer privacy law, aligned with but stricter than the Virginia CDPA, Colorado Privacy Act, and Connecticut CTDPA frameworks. It applies to businesses that either:
- Process the personal data of at least 35,000 Maryland consumers annually (excluding data processed solely to complete a payment transaction), or
- Derive more than 20% of gross revenue from selling the personal data of at least 10,000 Maryland consumers annually
The core obligations are familiar from other state privacy laws: consumer rights to access, correction, deletion, and portability; opt-out rights for targeted advertising and profiling; data minimization; purpose limitation; and security program requirements. What makes MODPA different — and materially more restrictive — is how it handles sensitive data.
The GLBA Entity-Level Exemption: What It Covers and What It Doesn’t
MODPA, like most state privacy laws, includes an exemption for “financial institutions and their affiliates governed by the Gramm-Leach-Bliley Act.” This is the entity-level exemption that many financial services teams assume provides a broad shield from state privacy law requirements.
The exemption is real. But it operates within the same constraint that undermined GLBA protection under Texas TDPSA and eroded GLBA safe harbors across Montana and Connecticut: GLBA’s Privacy Rule only covers nonpublic personal information (NPI) — data a consumer provides when obtaining or using a financial product or service.
MODPA’s GLBA exemption does not extend to data that falls outside NPI’s definition. And modern fintechs routinely collect, process, and sometimes sell data that GLBA was never designed to protect.
The Four Data Categories That Fall Through the Gap
| Data Type | GLBA NPI Coverage | MODPA Requirement |
|---|---|---|
| Transaction and account data | ✓ Covered | Exempt via GLBA |
| Precise geolocation (fraud detection, location-based features) | ✗ Not covered | Opt-in consent required; sale prohibited |
| Biometric data (face ID, fingerprint authentication) | ✗ Not covered | Opt-in consent required; sale prohibited |
| Pre-application behavioral analytics (site visits, ad clicks) | ✗ Not covered | Opt-out right; sale prohibited if sensitive data embedded |
| Employee personal data | ✗ Not covered | Full MODPA obligations apply |
Precise geolocation is one of the most common gaps. Fintechs use geolocation for fraud detection (flagging transactions from unexpected locations), location-based product features, and sometimes marketing. The transaction-fraud use is a legitimate operational necessity — but whether it’s covered by GLBA depends on the specific processing, not the general category.
Biometric data is where compliance programs frequently have the largest gap. If your mobile app uses Face ID or fingerprint authentication to access an account, that biometric template is being processed. Under MODPA, biometric data is sensitive data. Processing it requires opt-in consent. If your authentication vendor collects and stores that biometric data independently of the transaction, you need to understand that data flow carefully.
Marketing and behavioral data is where the fintech-marketing conflict becomes acute. Data collected through pixels, tracking scripts, or partnership analytics programs — user behavior before and between transactions — is generally not GLBA NPI. If that data includes geolocation, device health data, or is sold to third parties in any form, MODPA requirements apply to Maryland residents.
MODPA’s Unique Twist: The Outright Ban on Sensitive Data Sales
Most state privacy laws regulate sensitive data through enhanced consent requirements — you can still process and sell sensitive data if you get opt-in consent. MODPA breaks from that framework entirely.
Under MODPA, sensitive data may not be sold under any circumstances — including with consumer consent. Processing sensitive data is permitted only when strictly necessary to deliver a specific product or service the consumer requested from you.
This makes MODPA the most restrictive state privacy law in the country on this point. A fintech that sells a dataset to a marketing analytics company that includes biometric identifiers or precise geolocation records is in violation regardless of whether it disclosed this in its privacy policy or obtained consent. The sale is prohibited, not just regulated.
The “strictly necessary” standard for processing also matters. Using a consumer’s geolocation to detect that a transaction is occurring from an unusual location — a country the account holder has never transacted from — is a plausible argument for strictly necessary. Using that same geolocation data to populate a behavioral analytics model or determine ad targeting is not.
What the AG Enforcement Mechanism Looks Like
MODPA violations are treated as unfair, abusive, or deceptive trade practices under Maryland’s Consumer Protection Act. The Attorney General’s Division of Consumer Protection enforces MODPA directly. There is no private right of action.
Civil penalties structure:
- First notice: Up to $10,000 per violation
- Subsequent violations: Up to $25,000 per violation
A 60-day cure period currently applies after notice — the AG must give businesses 60 days to remediate before pursuing civil penalties. Importantly, that cure window sunsets on April 1, 2027. After that date, the AG can pursue penalties without a prior cure opportunity. If your MODPA compliance gap isn’t addressed by early 2027, you’re one complaint away from direct enforcement without the runway to fix it first.
The AG can also seek injunctive relief, restitution, and require appointment of compliance monitors for repeat violations or systematic violations affecting large numbers of consumers.
Three-Step Compliance Workstream for Fintechs
Step 1: Data Inventory for GLBA Gap Mapping
Start with what you collect, not what you think GLBA covers. Audit every data category collected from Maryland consumers — including data collected by marketing, product, and engineering — and ask: does this data relate to the provision of a financial product or service to that consumer?
Categories to audit specifically:
- Geolocation data (at what granularity, for what purpose)
- Biometric data (what is being stored, by whom, for how long)
- Health or wellness data (collected directly or through wellness integrations)
- Behavioral and engagement analytics (what third-party pixels and scripts run on your site)
- Pre-application data (data collected before a consumer becomes a customer)
The data classification framework your privacy program uses matters here. If your classification is built around GLBA NPI only, it won’t surface the gaps MODPA creates.
Step 2: Sensitive Data Controls Audit
For any sensitive data you process that falls outside GLBA coverage, determine whether:
- You have an opt-in consent mechanism in place (not just a disclosure)
- Processing is genuinely limited to what’s strictly necessary for the service
- Any third-party data sharing arrangements involving sensitive data exist
- Any data you sell (or receive revenue for sharing) includes sensitive data categories
If you’ve been relying on a consent mechanism that operates on an opt-out basis for sensitive data categories, that’s a MODPA gap. If your data sharing arrangements include a revenue component — even framed as analytics partnerships — review whether sensitive data is included in the scope.
Step 3: Privacy Notice and Consent Flow Updates
MODPA requires that your privacy notice (consumer-facing) discloses what sensitive data you collect and how you process it. If your privacy notice was drafted around GLBA’s limited notice requirements, it likely needs:
- Disclosure of sensitive data categories collected
- Explanation of the strictly necessary processing basis
- Opt-in consent mechanism for any processing beyond that basis
- Clear prohibition on data sales for sensitive categories
For Maryland specifically, your notice should reflect that sensitive data will not be sold, and should describe the specific operational purpose for which biometric or geolocation data is processed.
A Data Privacy Compliance Kit includes a state-law crosswalk matrix, MODPA-aligned data classification template, and DSAR workflow that covers the consent documentation requirements MODPA creates.
So What?
If your fintech has Maryland customers, operates an app with biometric authentication, or collects geolocation data for any purpose — fraud detection, location features, or marketing — you should be asking whether your current GLBA exemption assumption actually covers those data flows.
The gap isn’t theoretical. A pattern of GLBA exemption erosion across Montana, Connecticut, and Texas is now reaching Maryland. The practical consequence is that fintechs need a privacy program that maps to both GLBA and the state laws that operate around it — not one or the other.
Three things to do before the cure period sunsets:
- Run the data inventory: Know what data you collect that isn’t GLBA NPI
- Audit sensitive data flows: Identify any sale or third-party sharing of biometrics, geolocation, or health data from Maryland residents
- Update consent flows: If opt-in consent isn’t in place for sensitive data processing outside GLBA, put it in place before April 2027
The cure period is still running. Use it.
Sources:
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
When did MODPA enforcement begin?
Does the GLBA entity-level exemption fully protect banks and fintechs under MODPA?
What makes MODPA's sensitive data rules different from other state privacy laws?
What categories of data qualify as sensitive under MODPA?
What are the civil penalties for MODPA violations?
What does MODPA's 'strictly necessary' standard mean for sensitive data processing?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Keep reading
Related posts.
Data Privacy
Oregon's Privacy Law Has a Feature No Other State Has — and Financial Services Companies Are Probably in Scope
The Oregon Consumer Privacy Act's 30-day cure period ended January 1, 2026. The AG can now sue without notice. More importantly for financial services: the GLBA exemption is narrower than most assume, fintechs have significant exposure on non-NPI data, and Oregon requires something no other state does — a list of the specific named third parties that received consumer data.
Jul 17, 2026
Data Privacy
Connecticut's CTDPA Just Got a Lot Bigger — And Fintechs May Not Know They're Covered
Connecticut's CTDPA expanded on July 1, 2026 — lower thresholds, narrowed GLBA exemption, eliminated cure period, new profiling impact assessments. Here's what fintechs and nonbank lenders need to do now.
Jul 16, 2026
Data Privacy
NYDFS Part 500 in 2026: What 27 Consent Orders and $144M in Fines Tell You About Examiner Priorities
All Part 500 amended requirements are now in effect. NYDFS has 27 consent orders and $144M in fines under its belt. Here's what examiners are finding — and what to do before they show up at your door.
Jul 15, 2026