Maryland bars sale of residents’ location data without warrant

A coalition of 12 privacy and civil rights organizations filed a consumer complaint Wednesday asking Maryland Attorney General Anthony G. Brown to investigate seven data brokers for allegedly collecting and selling Marylanders’ geolocation data — including to federal immigration authorities — in violation of state privacy law. The complaint, authored by Georgetown University Law Center’s Technology Law Clinic, names Penlink, Thomson Reuters, Motorola, Insight LPR, LexisNexis, Flock Safety and ThunderCat Technology, alleging the companies sold sensitive personal information to law enforcement customers and, in several cases, to U.S. Immigration and Customs Enforcement.

The complaint was filed on behalf of We Are CASA — an advocacy group for working-class, Black, Latino, Indigenous and immigrant rights — along with 11 other privacy and civil rights organizations, including the Center for Democracy & Technology and the Electronic Privacy Information Center. It calls on Brown to “use the full force” of the state’s privacy laws and “take immediate action to rein in agencies’ use of commercially purchased data that enables mass surveillance of Americans without judicial, legislative, or public oversight.”

According to the complaint, Penlink sells cell phone location data through its Webloc program, while the other named companies sell car location data captured by automatic license plate readers. The complaint alleges the named companies are violating state privacy law by selling Marylanders’ location data, by selling data to ICE, or in some cases both.

Several of the companies named in the complaint have contracts with ICE. Penlink holds contracts with the agency. Thomson Reuters and LexisNexis provide data tools to ICE that contain a wide range of personal information drawn from public records and proprietary data sources, according to the complaint. ThunderCat Technology holds a contract with Homeland Security Investigations — a component of ICE — to provide individual taxpayer identification numbers, or ITIN data, to the agency.

Maryland’s 2024 Online Data Privacy Act, which state lawmakers updated this year with changes that took effect July 1, bars data brokers from collecting or sharing state residents’ sensitive data — including location data — unless it is needed to deliver a product or service the consumer requested, or unless the broker is responding to certain law enforcement demands. The law defines “precise geolocation data” as “information derived from technology that can precisely and accurately identify, within a radius of 1,750 feet, the specific location of a consumer, a mobile device, or a vehicle.” Under the law, data brokers are barred from selling Marylanders’ location data unless law enforcement has gone through a legal process to obtain a subpoena or warrant.

Maryland’s law also bars data brokers from selling information to agencies that enforce immigration law unless the law requires it or the agency presents a warrant — a provision Greg Nojeim, director of the Center for Democracy and Technology’s Security and Surveillance Project, called unique to the state.

“Data brokers in Maryland cannot comply with an ICE subpoena to seek a Marylander’s sensitive data — instead ICE must present a warrant,” Nojeim said. “This is important because ICE has abused its administrative subpoena authority to silence people who point out ICE abuses. Maryland is telling ICE, ‘Get a warrant if you want Marylanders’ sensitive data.’”

Two of the named companies, Penlink and Thomson Reuters, denied the allegations. In a statement, Thomson Reuters said, “We are confident that we are in compliance with all applicable laws and regulations governing our business and operations.” The company specifies on its website that its license plate recognition product “is not capable of tracking real time locations of a vehicle; it provides access to ad hoc images collected randomly.”

Penlink also denied the allegations. “The allegations against Penlink in the complaint are false, as Penlink does not process or sell precise location data of Marylanders in accordance with Maryland privacy law,” the company’s statement reads. “Penlink complies with applicable U.S. privacy laws and data-broker regulations, and we will continue to update our practices as data and privacy laws evolve.” Penlink did not respond to questions about a Baltimore County Police Department contract for Webloc previously reported by Citizen Lab, or about a proposed contract upgrade with Maryland State Police for Penlink’s PRX product. State records proposing that contract list “geolocation information” as one of the tool’s capabilities.

The complaint warns that without enforcement, “federal agencies will effectively be able to circumvent constitutional limits and judicial oversight altogether, and to conduct dragnet searches and go on fishing expeditions through Marylanders’ private lives in ways that they should not be able to do.”

George Escobar, executive director of We Are CASA, said in a statement that the organization’s direct services programming has encountered “parents worried about updating their address with state agencies, individuals increasingly cautious about engaging with any institution that collects personal data, even if they meet the program’s eligibility requirements.” He added, “Ensuring a more equitable Maryland for all starts with an investigation of these data companies and strict enforcement of our values as laid out in state law.”

None of the other named companies responded to requests for comment by deadline. Multiple emails to Flock Safety resulted in the same automated response: “Our media team is currently touching grass and taking a break. Unlike our cameras, we can’t work 24/7, so we’ll get back to you when we’ve had a snack and regained the ability to form coherent sentences.”

The complaint comes amid growing scrutiny of ICE’s use of commercially available personal data and surveillance tools to track and deport immigrants and to monitor protesters. Lawmakers from both parties have argued that law enforcement should not be able to purchase data they would otherwise need a warrant to obtain — a practice critics call the “data broker loophole” that they say circumvents Fourth Amendment protections against unreasonable searches and seizures. Congress has yet to pass legislation that would close the loophole.

Maryland is among several states that have moved to restrict what data brokers can do with their residents’ information. New Jersey, Virginia, Oregon and Connecticut have also recently banned the sale of some categories of sensitive data, including geolocation data.

The Maryland attorney general’s office declined to comment on the consumer complaint. Asked in late June about the new privacy provisions taking effect July 1, spokesperson Kelsey Hartman said, “Entities subject to the law should ensure they are in compliance.”