Politics

Privacy Groups Ask Maryland to Investigate Data Brokers Selling Location Data to Law Enforcement

Daniel CaldwellPublished 7d ago7 min readBased on 17 sources
Reading level
Privacy Groups Ask Maryland to Investigate Data Brokers Selling Location Data to Law Enforcement
Photo by RDNE Stock project on Pexels

Twelve privacy and civil rights organizations filed a consumer complaint with Maryland Attorney General Anthony G. Brown on August 19, 2026, asking him to investigate commercial data brokers for allegedly violating Maryland's data privacy law (NPR).

The complaint names Penlink, Thomson Reuters, Motorola, Insight LPR, LexisNexis, Flock Safety and ThunderCat Technology, among other companies. It says these firms collect and sell personal information and location data of Maryland residents to law enforcement customers in violation of state privacy law (NPR). Penlink sells cell phone location data through a program called Webloc. The other companies sell vehicle location data captured by license plate readers — cameras that photograph passing cars and record their plate numbers (NPR).

Several of the named companies have existing federal contracts. Penlink, Thomson Reuters and LexisNexis have contracts with U.S. Immigration and Customs Enforcement, or ICE. ThunderCat Technology holds a contract with Homeland Security Investigations, a division of ICE, to provide the agency with individual taxpayer identification number data (NPR).

Georgetown University Law Center's Technology Law Clinic wrote the complaint on behalf of We Are CASA and 11 other organizations, including the Center for Democracy & Technology and the Electronic Privacy Information Center (NPR; We Are CASA).

The complaint calls on Brown to use the full force of the state's privacy laws and take immediate action to rein in agencies' use of commercially purchased data, which the groups say enables mass surveillance of Americans without judicial, legislative or public oversight (NPR). We Are CASA executive director George Escobar said in a statement that the coalition's complaint calls for an investigation of the data companies and strict enforcement of Maryland's state law (NPR).

Penlink and Thomson Reuters denied the allegations and told NPR they were in compliance with the law (NPR).

Maryland's data privacy law stands out among state statutes because it bars data brokers from selling personal data to entities that assist with immigration enforcement (KGOU). That provision intersects directly with the ICE contracts held by several of the named companies. Maryland's 2026 Regular Session House Bill 711, enacted as Chapter 874, prohibits a controller from knowingly selling the personal data of a consumer if the controller knew or should have known certain circumstances regarding the sale (Maryland General Assembly).

We Are CASA made the Data Privacy Act a cornerstone of its 2026 Maryland legislative agenda, which focuses on protecting immigrant families from online tracking by ICE. The organization's Data Privacy Act passed in the Maryland House of Delegates and advanced to the Senate ahead of crossover — the deadline by which a bill must pass one chamber to stay alive (We Are CASA).

The Electronic Privacy Information Center, or EPIC, documents that agencies such as ICE and CBP purchase extensive personal data on immigrant communities from data brokers for use in enforcement campaigns, in the context of Maryland's H.B. 1220, the Data Broker Registry bill (EPIC). Written testimony submitted to the Maryland House Economic Matters Committee during the 2026 legislative session argued that data brokers buy and sell personal information without consumers' knowledge (Maryland General Assembly). February 24, 2026 testimony before the Maryland Senate Finance Committee noted that while the Maryland Online Data Privacy Act allows Marylanders to request that companies delete their personal data, the data broker industry continues to present issues (Maryland General Assembly). Laura Moy, Associate Professor of Law, testified before the same committee that data brokers may be exploiting legal gaps to share sensitive private information with law enforcement (Maryland General Assembly).

The complaint arrives against a backdrop of documented concerns about data broker practices and their intersection with law enforcement. The Brennan Center for Justice submitted a letter to the Consumer Financial Protection Bureau warning of national security risks posed by data brokers' largely unregulated collection, aggregation and sale of sensitive personal data (Brennan Center). The ACLU has documented that Flock Safety, one of the companies named in the complaint, has lied to local officials about its operations (ACLU). Flock Safety subsequently announced that it will reduce its standard data retention policy and provide more control over local data searches (ACLU). The ACLU states that Flock Safety is effectively automating and scaling the end run around checks and balances that law enforcement data broker purchases represent (ACLU). Police in Maryland and Michigan are publicly known to have wrongfully arrested people while exploiting the data broker loophole, according to an ACLU/NYCLU report (ACLU).

The Maryland attorney general's office has been active on related privacy concerns. In January 2026, Brown's office joined 21 other state attorneys general in calling out federal threats against data privacy advocates who allege federal agents are using private data to intimidate observers and activists during an operation referred to as "Operation Metro" (Maryland Attorney General).

Senate Finance Committee testimony uploaded during the 2026 legislative session referenced the attorney general investigating a data broker's failure to register and called for funding a privacy unit to enforce Maryland's privacy laws (Maryland General Assembly).

The broader context here is a state-level enforcement push meeting a federal surveillance apparatus that has grown reliant on commercial data purchases to circumvent warrant requirements. Maryland's statutory framework is distinctive in two respects: the immigration-enforcement sale prohibition and the Data Broker Registry mechanism under H.B. 1220. The complaint tests whether the attorney general will deploy enforcement tools that the legislature built but that have not yet been exercised against brokers supplying federal agencies. Utah's recently passed digital identity bill, which the ACLU describes as the nation's strongest, includes a "duty of loyalty" requiring participants in an ID system to act in individuals' best interests (ACLU), suggesting that states are beginning to impose fiduciary-style obligations on data handlers, a trend that could shape how Maryland's existing statutes are interpreted and enforced.

The companies named in the complaint span both phone-location and license-plate-reader data streams, two of the primary commercial surveillance channels that law enforcement agencies access without a warrant or court order. The complaint's framing of these purchases as enabling mass surveillance without judicial, legislative or public oversight aligns with arguments that the ACLU, EPIC and the Brennan Center have advanced separately across federal and state venues.