Privacy Groups Urge MD to Investigate Data Broker Industry

Privacy advocates call on Maryland to investigate data brokers

Privacy advocates call on Maryland to investigate data brokersImage Credit: NPR Politics

Key Points

  • The Call to Action: The complaint urges the Attorney General to "use the full force" of state law to investigate the named companies and "take immediate action to rein in agencies' use of commercially purchased data."
  • The Human Impact: George Escobar, executive director of We Are CASA, highlighted the chilling effect these practices have on communities. "We have witnessed parents worried about updating their address with state agencies, [and] individuals increasingly cautious about engaging with any institution that collects personal data," he stated, emphasizing the need for strict enforcement to build a "more equitable Maryland."
  • Precise Geolocation Data: The statute defines this as "information derived from technology that can precisely and accurately identify, within a radius of 1,750 feet, the specific location of a consumer, a mobile device, or a vehicle." The sale of such data without explicit consumer consent is a key point of contention.
  • Named Companies: The list includes Penlink, Thomson Reuters, Motorola, Insight LPR, LexisNexis, Flock Safety, and ThunderCat Technology.
  • Alleged Activities: Penlink is accused of selling cellphone location data through its "Webloc" program. The other firms are primarily cited for selling vehicle location data captured by extensive networks of license plate readers.

Privacy Advocates Call on Maryland to Investigate Data Brokers

A coalition of privacy and civil rights organizations has formally called on Maryland's attorney general to launch an investigation into some of the nation's largest data brokers, alleging they are violating the state's stringent new privacy laws. The complaint claims these companies are collecting and selling the sensitive location data of Maryland residents, including to federal immigration authorities, setting the stage for a major legal test of state-level data privacy enforcement.

The consumer complaint, filed Wednesday with Attorney General Anthony G. Brown, targets a slate of prominent companies, including Thomson Reuters, LexisNexis, and Penlink. It argues that their business practices create a system of mass surveillance that circumvents judicial oversight and directly contravenes the Maryland Online Data Privacy Act, considered one of the most robust in the United States.

This action places a spotlight on the burgeoning and often opaque data brokerage industry, a multi-billion dollar market that profits from the aggregation and sale of personal information. The outcome in Maryland could establish a significant precedent, influencing how other states regulate the commercial data pipeline that increasingly feeds into both corporate and government surveillance systems.

The Core Allegations

At the heart of the complaint is the assertion that data brokers are systematically violating Maryland law by harvesting and monetizing two primary types of information: precise geolocation data from cellphones and vehicle location data from automated license plate readers (ALPRs).

The coalition, led by the Georgetown University Law Center's Technology Law Clinic on behalf of immigrant rights group We Are CASA and 11 other organizations, alleges these activities enable federal agencies like U.S. Immigration and Customs Enforcement (ICE) to track individuals without a warrant.

  • The Call to Action: The complaint urges the Attorney General to "use the full force" of state law to investigate the named companies and "take immediate action to rein in agencies' use of commercially purchased data."

  • The Human Impact: George Escobar, executive director of We Are CASA, highlighted the chilling effect these practices have on communities. "We have witnessed parents worried about updating their address with state agencies, [and] individuals increasingly cautious about engaging with any institution that collects personal data," he stated, emphasizing the need for strict enforcement to build a "more equitable Maryland."

A Test for Maryland's Landmark Law

The legal battleground is Maryland's new privacy statute, which sets a high bar for data protection. The law's power lies in its specific definition of what constitutes sensitive information.

  • Precise Geolocation Data: The statute defines this as "information derived from technology that can precisely and accurately identify, within a radius of 1,750 feet, the specific location of a consumer, a mobile device, or a vehicle." The sale of such data without explicit consumer consent is a key point of contention.

This case represents one of the first major challenges under the new law, and its interpretation by the Attorney General's office will be closely watched by businesses and privacy advocates nationwide. For companies operating across state lines, it underscores the growing complexity and financial risk of navigating a patchwork of disparate state privacy regulations.

The Companies in the Crosshairs

The complaint names several key players in the data and surveillance technology sectors, accusing them of providing data to law enforcement and federal agencies, including ICE and its investigative arm, Homeland Security Investigations (HSI).

  • Named Companies: The list includes Penlink, Thomson Reuters, Motorola, Insight LPR, LexisNexis, Flock Safety, and ThunderCat Technology.

  • Alleged Activities: Penlink is accused of selling cellphone location data through its "Webloc" program. The other firms are primarily cited for selling vehicle location data captured by extensive networks of license plate readers.

  • Federal Contracts: The complaint details specific contractual relationships. Thomson Reuters and LexisNexis are identified as providing broad data-access tools to ICE. Penlink holds a direct contract with the agency, while ThunderCat Technology allegedly provides individual taxpayer identification numbers (ITIN) data to HSI.

Corporate Denials and Responses

Several of the accused companies have pushed back strongly against the allegations, asserting their compliance with all applicable laws.

  • Thomson Reuters: In a statement to NPR, the company expressed confidence that it is "in compliance with all applicable laws and regulations." It clarified that its license plate recognition product provides access to historical, randomly collected images and is "not capable of tracking real time locations of a vehicle."

  • Penlink: The company issued a firm denial, stating, "The allegations against Penlink in the complaint are false, as Penlink does not process or sell precise location data of Marylanders in accordance with Maryland privacy law." Penlink affirmed its commitment to complying with evolving privacy regulations and later noted it had requested the complainants withdraw the "false allegations."

The complaint specifically references a Baltimore County Police contract for Penlink's Webloc tool and a proposed Maryland State Police contract for its PLX product, which state records noted included "geolocation information." Penlink has since clarified that its PLX platform is a "warrant-based digital evidence platform" used to organize, not provide, geolocation data obtained by law enforcement.

What Comes Next: The Broader Implications

The Maryland Attorney General's office must now decide whether to launch a formal investigation based on the complaint. The decision carries significant weight for the data brokerage industry and the future of digital privacy rights.

  • Regulatory Precedent: An enforcement action would signal that states with strong privacy laws are prepared to aggressively police the data market, potentially forcing a shift in industry practices beyond Maryland's borders.

  • Business and Financial Risk: For the named companies, an investigation poses substantial legal, financial, and reputational risk. It could jeopardize lucrative government contracts and lead to significant fines, impacting investor confidence and stock valuations.

  • The Surveillance Debate: This case is a microcosm of a larger national debate over government use of commercially available data. By purchasing data sets from brokers, agencies can often bypass the warrant requirements typically needed to obtain such information directly from telecommunication or tech companies.

As states continue to legislate on data privacy in the absence of a comprehensive federal law, this complaint in Maryland serves as a critical test case. The outcome will not only determine the enforceability of the state's own rules but will also send a powerful message to a data-driven industry facing increasing scrutiny and a complex, high-stakes regulatory landscape.

Source: NPR Politics