A coalition of privacy and civil rights groups filed a consumer complaint Wednesday asking Maryland Attorney General Anthony G. Brown to investigate several data brokers for alleged violations of state privacy laws. The complaint, authored by Georgetown University Law Center’s Technology Law Clinic, alleges that these companies are collecting and selling Marylanders' geolocation and personal data to law enforcement and federal immigration agencies without sufficient oversight.
The action follows the implementation of the Maryland Online Data Privacy Act, which was passed in 2024 and updated during the most recent legislative session. The law prohibits data brokers from selling sensitive information, such as precise location data, unless they are responding to specific law enforcement demands like a warrant or subpoena. Maryland's statute is unique for its specific restrictions on selling personal data to agencies that enforce immigration law, such as U.S. Immigration and Customs Enforcement (ICE).
The complaint names several companies, including Penlink, Thomson Reuters, Motorola, Insight LPR, LexisNexis, and Flock Safety. It alleges these firms sell vehicle location data from license plate readers or cellphone location information to government entities. Penlink and Thomson Reuters both denied the allegations, stating they comply with all applicable laws. Thomson Reuters noted its license plate product provides random images rather than real-time tracking, while Penlink stated it does not sell precise location data as defined by Maryland law.
The concrete change for Marylanders involves how their personal information is handled by private companies and accessed by government agencies like ICE. If the Attorney General takes enforcement action, residents may see stricter controls on how data brokers package and sell their location history, potentially preventing federal agencies from using commercial databases for immigration enforcement or protest monitoring. Advocates state that immigrant communities, in particular, have expressed concern that updating addresses or using public services could lead to their data being sold to federal authorities.
Knock-on effects could influence privacy policy in other states like New Jersey, Virginia, Oregon, and Connecticut, which have also recently restricted the sale of sensitive data. Because Maryland's law specifically requires ICE to obtain a warrant rather than a subpoena for sensitive data, a successful enforcement action would set a precedent for how state laws can limit federal administrative powers. The Maryland Attorney General’s office declined to comment on the specific complaint, but previously stated that all entities must ensure they are in compliance with the new provisions that took effect on July 1. No specific hearing dates or deadlines for the investigation have been announced.
