HB0711, the Data Privacy Act, expands and clarifies Maryland’s consumer-data privacy rules and adds new restrictions tied to immigration enforcement. The bill amends definitions in the state’s commercial data privacy subtitle, including “personal data,” “precise geolocation data,” “publicly available information,” and “sensitive data,” and it broadens the treatment of sensitive data to include sensitive attributes such as race, religion, health data, sexual orientation, gender identity, citizenship or immigration status, biometric data, child data, and precise geolocation data. It also clarifies that publicly available information obtained from a governmental record must be used in compliance with any restrictions or terms of use imposed by the government entity.
The bill prohibits controllers from collecting, processing, or sharing sensitive data except when strictly necessary to provide a requested product or service, and it bars the sale of sensitive data. It further prohibits selling a consumer’s personal data when the seller knows or should know the buyer intends to use it for immigration enforcement, and it separately bars knowingly selling personal data to a governmental unit that has recently engaged in or supported civil immigration enforcement through personnel or material resources. The bill also limits controllers’ ability to comply with certain subpoenas, summonses, and cooperation requests when they relate solely to immigration enforcement, while preserving compliance with valid warrants and other lawful obligations.
HB0711 also changes public-records and law-enforcement access rules. Custodians of public records must adopt reasonable rules to prevent unauthorized disclosure or inspection and must take reasonable steps to determine whether a requester is seeking records for immigration-law enforcement. The bill requires denial of access to certain public records, photographs, and facial-recognition searches when the request is for immigration enforcement unless supported by a valid warrant. It also requires reporting to the General Assembly on such requests and directs the Motor Vehicle Administration, State Police, and the Department of Public Safety and Correctional Services to adopt regulations and procedures to implement the new requirements.
In addition, the bill addresses law-enforcement databases and message switching systems by requiring operators to deny access to persons seeking access for immigration enforcement unless they present a valid warrant, and to collect identifying information and a sworn statement from users who are not presenting such a warrant. Finally, it requires all governmental entities, in consultation with the Department of Information Technology, to develop and publish procedures by July 1, 2026, to prevent the sale and redisclosure of personal records and sensitive data containing sensitive attributes, with an emphasis on limiting secondary commercial markets and protecting resident privacy.
The overall sentiment reflected by the bill text is strongly privacy-protective and restrictive toward the use of state-held data for immigration enforcement. No committee transcripts or recorded votes were provided, so there is no additional evidence of debate or opposition in the supplied materials. The main points of potential contention are the bill’s immigration-enforcement restrictions, the added compliance and reporting obligations for custodians and agencies, and the expanded limits on data sharing and law-enforcement access, especially where those limits intersect with subpoenas, cooperation requests, and database access.
HB0711 amends Maryland’s Commercial Law, General Provisions, Public Safety, and State Government articles to create stronger limits on the collection, sale, disclosure, and use of personal data, especially sensitive data and public-record information. It adds new restrictions on controllers’ data practices, narrows certain exceptions for governmental compliance, imposes duties on custodians of public records, and requires state agencies and governmental entities to adopt regulations, procedures, and reporting practices to prevent data use for immigration enforcement and to reduce redisclosure of sensitive government-held data.
The bill appears to have been framed as a privacy and civil-liberties measure, with a clear policy goal of limiting the use of personal and government-held data for immigration enforcement and commercial exploitation. Because no committee transcripts or vote breakdowns were provided, there is no documented floor or committee sentiment to summarize beyond the enacted text itself. The statutory changes suggest a strong pro-privacy, pro-limitation posture from the bill’s supporters.
The most notable points of contention are likely to be the immigration-enforcement provisions and the breadth of the restrictions on data sharing and law-enforcement access. The bill limits sales of personal data to entities involved in civil immigration enforcement, restricts compliance with certain subpoenas and summonses tied to immigration enforcement, and requires custodians to screen requests for immigration-related purposes. These provisions may raise concerns among law-enforcement agencies, data holders, and governmental units about operational burdens, access to information, and the scope of state interference with federal or local enforcement activities.