News

Privacy advocates call on Maryland to investigate data brokers

Foto : Lisa Hernandez - ecorescuezone.com
Daftar Isi
  1. Coalition Demands Maryland Attorney General Probe Data Brokers Selling Residents’ Location Data
  2. Related Reading
  3. Frequently Asked Questions

Coalition Demands Maryland Attorney General Probe Data Brokers Selling Residents’ Location Data

Ecorescuezone.com – A broad alliance of privacy advocates and civil rights organizations filed a formal consumer complaint this week urging Maryland’s top law-enforcement official to open an investigation into commercial data brokers accused of harvesting and reselling Marylanders’ geolocation information in ways that conflict with the state’s privacy statutes. The filing lands at a moment of heightened tension: federal immigration enforcement agencies have intensified their reliance on commercially purchased personal data and surveillance technologies to locate, track, and deport immigrants, while also monitoring protest activity across the country.

The complaint specifically names Penlink, Thomson Reuters, Motorola, Insight LPR, LexisNexis, Flock Safety, and other firms, alleging that they collect and sell personal information and location data on Maryland residents to law-enforcement customers in violation of state privacy law. Penlink, according to the filing, distributes cellphone location data through its Webloc program. The remaining companies are accused of selling vehicle location data captured by license-plate reader systems installed along roadways.

The Federal Immigration Connection

Several of the named firms maintain active contracts with U.S. Immigration and Customs Enforcement. Penlink is among them. Thomson Reuters and LexisNexis supply ICE with data-search tools that aggregate personal information drawn from public records and proprietary data sources. The complaint also identifies ThunderCat Technology, which holds a contract with Homeland Security Investigations — a division within ICE — to furnish the agency with individual taxpayer identification number (ITIN) data.

For Maryland residents, particularly immigrants and members of communities already under federal scrutiny, the implications are direct: data collected by commercial brokers may end up in the hands of federal agents without any judicial warrant, legislative authorization, or public oversight.

What Maryland’s Privacy Law Says

Maryland has enacted some of the most protective data-privacy provisions in the United States. Under the state’s framework, “precise geolocation data” is defined as information derived from technology capable of identifying, within a radius of 1,750 feet, the specific location of a consumer, a mobile device, or a vehicle. The complaint argues that the named brokers’ products and services fall squarely within that definition and that their sale to government agencies without consumer consent or adequate notice breaches the statute.

The filing calls on Maryland Attorney General Anthony G. Brown to deploy the full authority of the state’s privacy laws and act swiftly to curb what it describes as agencies’ use of commercially purchased data that enables mass surveillance of Americans without judicial, legislative, or public oversight.

“Use the full force” of the state’s strong privacy laws, “and take immediate action to rein in agencies’ use of commercially purchased data that enables mass surveillance of Americans without judicial, legislative, or public oversight.”

Who Authored the Complaint

The consumer complaint was drafted by the Technology Law Clinic at Georgetown University Law Center on behalf of We Are CASA, an organization advocating for working-class, Black, Latino, Indigenous, and immigrant communities, together with eleven additional organizations focused on privacy and civil rights, including the Center for Democracy & Technology and the Electronic Privacy Information Center.

George Escobar, executive director of We Are CASA, described the practical consequences the organization has observed in its direct-services work:

“Through our direct services programming, we have witnessed parents worried about updating their address with state agencies, individuals increasingly cautious about engaging with any institution that collects personal data, even if they meet the program’s eligibility requirements.”

The accompanying statement added:

“Ensuring a more equitable Maryland for all starts with an investigation of these data companies and strict enforcement of our values as laid out in state law.”

Company Responses

Two of the named data brokers, Penlink and Thomson Reuters, publicly denied the allegations and stated they were operating in compliance with applicable law.

A statement from Thomson Reuters read:

“We are confident that we are in compliance with all applicable laws and regulations governing our business and operations.”

The company further noted on its website that its license-plate recognition product “is not capable of tracking real time locations of a vehicle; it provides access to ad hoc images collected randomly.”

Penlink issued its own rebuttal:

“The allegations against Penlink in the complaint are false, as Penlink does not process or sell precise location data of Marylanders in accordance with Maryland privacy law. Penlink complies with applicable U.S. privacy laws and data-broker regulations, and we will continue to update our practices as data and privacy laws evolve.”

In a follow-up comment issued after the initial reporting, Penlink added that it had reached out to We Are CASA and the supporting organizations to request that the complaint against it be withdrawn and the allegations corrected.

Background and Broader Implications

Data brokers occupy a largely invisible layer of the American information economy. They aggregate records from public filings, mobile-carrier metadata, license-plate reader networks, and proprietary databases, then sell compiled dossiers to advertisers, insurers, and government agencies. Few consumers know their location traces are being packaged and resold, and state privacy statutes — including Maryland’s — have only recently begun to impose notice and consent requirements on that trade.

The complaint also references a Baltimore County Police Department contract for Penlink’s Webloc service, previously documented by Citizen Lab, as well as a proposed contract upgrade. Penlink did not respond to questions about either arrangement.

If the state attorney general opens a formal inquiry, the outcome could set a precedent for how aggressively mid-Atlantic states enforce their privacy statutes against commercial data brokers whose customers include federal agencies. For Maryland’s immigrant communities and other residents wary of surveillance, the stakes extend well beyond a single state’s regulatory ledger.

Frequently Asked Questions

What is Privacy advocates call on Maryland to investigate?

Privacy advocates call on Maryland to investigate is the main topic of this guide. The article explains the context, practical details, and next steps readers should understand.

Why does Privacy advocates call on Maryland to investigate matter?

Privacy advocates call on Maryland to investigate matters because readers are looking for a useful answer, not just a short summary. Good content should match search intent and help them decide what to do next.

Leave a Comment