Data Privacy - Consumer Data, Public Records, and Message Switching System (Data Privacy Act)
HB711, the Data Privacy Act, expands Maryland’s consumer privacy law and related public-records rules with a particular focus on immigration enforcement and sensitive personal data. In the commercial privacy subtitle, the bill broadens the definition of sensitive data/sensitive attributes to include items such as citizenship or immigration status, precise geolocation data, biometric data, child data, and inferred data tied to those categories. It also tightens restrictions on controllers’ use of personal data, including limits on selling data when the buyer seeks to use it for immigration enforcement or when the buyer is a government unit that has recently supported civil immigration enforcement.
The bill also changes how controllers and processors may respond to government demands for data. It preserves general authority to comply with laws, subpoenas, and investigations, but creates exceptions for requests tied solely to immigration enforcement, unless a valid warrant is presented. The measure further restricts disclosure of public records and motor vehicle information for immigration-enforcement purposes, requires custodians to adopt rules to prevent unauthorized disclosure, and directs certain state agencies to report immigration-related access requests. It additionally requires entities operating law-enforcement databases or a message switching system to deny access for immigration-enforcement purposes absent a warrant and to adopt implementing regulations. Finally, it requires state and local governmental entities to develop procedures to prevent the sale and redisclosure of personal records and sensitive data containing sensitive attributes.
The bill’s impact on state law is broad: it amends the Maryland Commercial Law Article, General Provisions Article, Public Safety Article, and State Government Article. It creates new compliance obligations for private data controllers, public-record custodians, motor vehicle and public safety agencies, and other governmental entities that handle or share sensitive information. It also adds reporting and rulemaking duties, and it is scheduled to take effect July 1, 2026.
The overall sentiment reflected in the voting history is favorable, with the bill passing third reading in both chambers. At the same time, the rejection of a floor amendment suggests there was some disagreement over the bill’s scope or details, even though the underlying measure ultimately advanced. No committee transcript was provided, so the available record shows support for the bill’s privacy and immigration-related restrictions, but limited evidence of the specific arguments made in debate.
The main points of contention appear to center on the immigration-enforcement provisions and the limits they place on data sharing with government entities. The bill distinguishes between ordinary law-enforcement cooperation and requests tied to civil immigration enforcement, which may raise concerns for supporters of broader law-enforcement access and for entities that rely on routine compliance with subpoenas or interagency requests. Another likely area of debate is the expanded treatment of sensitive data and the operational burden on businesses and agencies that must revise policies, procedures, and reporting practices.
HB711 amends Maryland’s consumer data privacy framework and related public-records and law-enforcement access rules. It adds or revises definitions in the Commercial Law Article, restricts certain sales and disclosures of personal data, limits compliance with immigration-enforcement-related requests absent a warrant, and requires governmental entities to adopt procedures to prevent the sale and redisclosure of sensitive records. It also imposes new duties on custodians, the Motor Vehicle Administration, the Department of State Police, the Department of Public Safety and Correctional Services, and entities operating databases or message switching systems, including rulemaking and reporting requirements.
The bill appears to have broad legislative support, as reflected by successful third-reading votes in both chambers. The rejection of at least one floor amendment indicates some disagreement over particulars, but the final votes suggest the core privacy and anti-immigration-enforcement provisions were acceptable to a majority. No committee transcript was available, so the record does not show detailed debate, but the voting pattern points to generally favorable sentiment.
The most notable contention is the bill’s treatment of immigration enforcement. HB711 limits sales of personal data to buyers seeking it for immigration enforcement and restricts compliance with subpoenas, summonses, and cooperation requests tied to civil immigration enforcement unless a valid warrant is presented. Critics may view these provisions as limiting cooperation with government authorities, while supporters likely see them as necessary privacy protections. A second area of possible contention is the expanded definition of sensitive data and the resulting compliance burden on businesses and public agencies that must adjust data-handling practices, adopt new procedures, and report certain requests.