
A coalition of civil rights and privacy organizations has filed a 29-page complaint accusing seven commercial data and technology companies of violating Maryland's data privacy law by selling residents' location information to federal immigration authorities without a warrant. The groups, led by We Are CASA, are asking the Maryland Attorney General to enforce a statute that is barely a month old in terms of its active enforcement window, according to reporting from CBS News Baltimore.
The complaint names Penlink, Motorola, Thomson Reuters, Insight LPR, LexisNexis, Flock Safety, and ThunderCat Technology as the companies allegedly harvesting and selling Marylanders' cellphone location and automatic license plate reader data to agencies including U.S. Immigration and Customs Enforcement, according to CBS News Baltimore. Reporter Dennis Valera detailed how the coalition says these companies are violating the Maryland Data Privacy Act by funneling sensitive tracking data to federal authorities without judicial warrants, per the complaint's allegations. As reported by NPR, this alleged conduct strikes at the heart of a law designed specifically to block that kind of warrantless data pipeline.
A Law Built to Block Warrantless Tracking
The Maryland Online Data Privacy Act contains a provision that NPR describes as unique among state privacy statutes: a ban on data brokers selling personal data to agencies assisting with federal immigration enforcement, paired with a requirement that ICE present an actual court warrant rather than a mere administrative subpoena. The law officially took effect on October 1, 2025, but its enforcement rules only apply to data processing activities occurring on or after April 1, 2026, according to compliance guidance published by Didomi. That timing means the coalition's complaint arrives near the very start of the law's operational life.
Legal analysis from Baker Donelson shows the statute applies to businesses that processed personal data belonging to at least 35,000 Maryland consumers, or at least 10,000 consumers while also drawing more than 20 percent of gross revenue from data sales. The same analysis notes that Maryland law explicitly prohibits companies from collecting, processing, or selling sensitive personal data — including precise geolocation within 1,750 feet, health data, and immigration status — unless doing so is strictly necessary to provide a requested product or service. Those thresholds and restrictions form the legal backbone of the allegations against the seven named companies.
Lawmakers Kept Tightening the Rules
The current fight did not emerge in isolation. Following the 2024 passage of the underlying privacy act, Maryland legislators enacted additional statutory updates during the 2026 legislative session, which took effect in July, specifically to further restrict state data sharing with federal immigration enforcement, per NPR's reporting. That legislative momentum echoes the grassroots pressure Hoodline documented in a last-minute Annapolis rally earlier this year, when immigrant advocates pushed lawmakers to pass data privacy and sanctuary measures before the legislative session closed.
The stakes around commercial license plate reader technology are not abstract for Maryland residents. Hoodline previously reported on Baltimore's $1.46 million plate tracker deal with Motorola, one of the very companies now named in the coalition's complaint, examining at the time how state statutory restrictions were meant to limit commercial ALPR data sharing.
Only Two Companies Have Responded
Of the seven companies named in the complaint, only Penlink and Thomson Reuters have responded to inquiries, and both maintain that their data handling practices fully comply with Maryland law, the CBS News Baltimore report notes. Penlink stated it reached out to coalition members while asserting its compliance posture, according to the same account. Motorola, LexisNexis, Insight LPR, Flock Safety, and ThunderCat Technology have not offered public responses to the allegations.
The Office of Maryland Attorney General Anthony Brown has acknowledged receiving the coalition's 29-page filing and confirmed that state attorneys are actively reviewing the allegations, per CBS News Baltimore. Because the Maryland Online Data Privacy Act grants sole enforcement authority to the Attorney General rather than allowing individual consumers to sue, that review will determine whether the state pursues formal enforcement action. Compliance analysis from Didomi notes the law sets civil penalties of up to $10,000 per violation, rising to as much as $25,000 for repeat infractions under consumer protection law.
What happens next rests entirely with the Attorney General's office, since Maryland's privacy framework deliberately omitted a private right of action for residents to file their own lawsuits. Civil rights and privacy organizations behind the complaint are pressing the state to treat the case as a test of whether its data privacy statute has real teeth against companies supplying federal immigration enforcement with tracking data gathered from Maryland residents.









