MODPA and VCDPA: the two privacy laws Delmarva businesses keep missing.
If you run a business on the Delmarva Peninsula, some of your customers live in Maryland and some live in Virginia. Both states now have consumer privacy laws in force. Most local owners have heard of neither.
The two laws, briefly
Maryland — MODPA (Maryland Online Data Privacy Act, Md. Code, Com. Law § 14-4701 et seq.) became effective October 1, 2025. It is one of the strictest state privacy laws in the country: a hard data-minimization rule that consent cannot waive, an outright prohibition on selling sensitive data, opt-in consent for sensitive data, and a requirement to honor opt-out preference signals like Global Privacy Control (GPC). Maryland's Attorney General has a discretionary cure period that runs through April 1, 2027 — that is enforcement discretion, not immunity, and it doesn't extend to private claims.
Virginia — VCDPA (Virginia Consumer Data Protection Act, Va. Code § 59.1-575 et seq.) has been in force since January 1, 2023. It gives consumers rights to access, correct, and delete their data, to opt out of sale and targeted advertising, and — uniquely — to appeal a denied request. Virginia has been actively enforcing: the state has already extracted settlements from companies that failed to honor opt-outs.
Who is in scope
MODPA generally covers those controlling personal data of 35,000+ Maryland consumers(or 10,000+ if more than 20% of gross revenue comes from selling personal data — payment-transaction data doesn't count toward that number). VCDPA's thresholds are 100,000 Virginia consumers, or 25,000+ if more than 50% of gross revenue comes from selling personal data.
Even below threshold, the practical duties don't vanish: if your website runs ad trackers, you still need a privacy policy, a cookies notice, and honest handling of consent. And thresholds measure consumers, not revenue — a modest shop with heavy web traffic can clear them.
What a compliance scan checks
A passive scan reads your public pages the way any visitor's browser would — no forms submitted, no accounts created, no JavaScript executed on your site — and looks for the signals both regulators look at first:
- • A readable privacy policy and cookies/tracking notice
- • A consent banner if trackers are present
- • Which trackers fire on the homepage (Google, Meta, TikTok, Hotjar…)
- • GPC handling — the opt-out signal MODPA expects you to honor
- • Whether your policy states a position on selling sensitive data (MODPA prohibits it)
- • Virginia rights language including the appeal path
That's what the free Compliance Guard scan runs — in about a minute, scored A–F, with a plain-English fix list.
What this article is not
Not legal advice. This is an engineering read of what the statutes require; it doesn't establish compliance with MODPA, VCDPA, or any law, and generated policies are starting templates. Have counsel review before relying on any policy. And beware any vendor selling a "certified compliant" badge — no such certification exists for either law.
Check your site free
The free scan runs in about a minute. Founding pricing ends September 30, 2026 (end of day Eastern). After that the setup price doubles to $2,000 and monitoring doubles to $400/mo.