A complaint from civil-rights and privacy organizations is asking Maryland’s attorney general to enforce the Maryland Online Data Privacy Act, but the available evidence does not establish that any named company has violated the law. For readers, the immediate issue is less a confirmed enforcement case than a coverage and compliance question: which businesses may be subject to the law, and what happens if the attorney general acts?
What the complaint establishes—and what it does not
CBS Baltimore reported on Aug. 21, 2026, that a group of civil-rights and privacy organizations had filed a complaint alleging that companies were violating Maryland’s data privacy law. The report says the groups want the attorney general to enforce the statute.

That is evidence of a formal complaint and an enforcement request. It is not evidence of a final government determination. The supplied report does not name the companies involved, describe each alleged practice or say whether the attorney general has opened an investigation. Those gaps matter because the practical consequences could differ depending on the businesses, data categories and conduct at issue.
Why businesses outside traditional privacy categories may still be affected
The Maryland Online Data Privacy Act took effect on Oct. 1, 2025, and enforcement by the Maryland attorney general began on April 1, 2026, according to a Baker Donelson legal analysis published before the law took effect.
The analysis says the law applies to entities doing business in Maryland or providing products or services targeted to Maryland residents when, during the previous calendar year, they either controlled or processed the personal data of at least 35,000 consumers, excluding data processed solely to complete a payment transaction, or handled data from at least 10,000 consumers while deriving more than 20% of gross revenue from selling personal data.
The coverage rules create a decision point for companies that may assume another exemption protects them. Baker Donelson says MODPA has limited entity-level exemptions and does not broadly exempt nonprofit organizations, higher education institutions, health care entities covered by HIPAA or small businesses. The analysis also identifies data-level exemptions, including certain health information regulated by HIPAA, education records subject to FERPA and information handled by consumer credit reporting agencies under the Fair Credit Reporting Act.
That distinction is consequential. A company may need to examine both its organizational status and the type of data it processes rather than relying on a familiar industry label. The result could be additional legal review, data inventories or changes to collection practices for businesses that fall within the statute.
The trade-off for consumers is broader scrutiny, not a guaranteed outcome
For consumers, the complaint signals that privacy organizations are pressing regulators to examine how companies collect and use personal data. But a complaint alone does not show that consumer access, prices or services have already changed.
Compliance can impose costs on businesses through legal work, operational reviews and changes to data systems. Those costs may influence how a company designs a service or what information it requests, but the evidence pack does not quantify those effects or show that a particular company has passed them to customers. It would be premature to claim that the law will raise prices, reduce access or produce uniform privacy improvements.
The Baker Donelson analysis describes a data-minimization requirement under which controllers must limit personal-data collection to what is reasonably necessary and proportionate to provide or maintain a specific product or service request. That mechanism gives the dispute a practical center: whether a company’s data collection is connected to a defined service need, rather than simply whether it has a privacy policy.
What readers should watch next
Businesses serving Maryland residents should first determine whether their data volume, revenue mix and exemptions place them within MODPA’s scope. They should then separate verified legal duties from allegations made in the complaint.
Consumers should treat the current story as an enforcement question still in development. The most meaningful next signal will be a public response, investigation or enforcement decision from the Maryland attorney general. Until then, the available evidence supports concern about compliance practices, not a final conclusion that the accused companies broke the law.
The Maryland complaint is best understood as an enforcement test, not a confirmed finding against named companies. The law’s relatively low coverage thresholds and limited entity-level exemptions mean businesses serving Maryland residents may need to review their status even if they have relied on exemptions in other privacy regimes. For consumers, the practical outcome remains unsettled: the evidence does not show price, access or service changes. A public response or enforcement decision from the Maryland attorney general would clarify whether the allegations lead to a formal case.
Sources and methodology
- Groups say companies are violating Maryland Data Privacy Act - CBS News - https://www.cbsnews.com/baltimore/video/groups-say-companies-are-violating-maryland-data-privacy-act
- Practical Next Steps for Businesses as Maryland's Updated Consumer ... - https://www.bakerdonelson.com/practical-next-steps-for-businesses-as-marylands-updated-consumer-data-privacy-laws-take-effect-in-october
- What Makes the Maryland Online Data Privacy Act (MODPA) Different? - https://www.osano.com/articles/maryland-online-data-privacy-act-modpa
- What the Maryland Online Data Privacy Act means for you - PIRG - https://pirg.org/edfund/resources/what-the-maryland-online-data-privacy-act-means-for-you


